|
|
Log in / Subscribe / Register

pam: arbitrary code execution

Package(s): pam CVE #(s): CVE-2011-3148 CVE-2011-3149
Created: October 24, 2011 Updated: March 11, 2013
Description: From the Debian advisory:

Kees Cook of the ChromeOS security team discovered a buffer overflow in pam_env, a PAM module to set environment variables through the PAM stack, which allowed the execution of arbitrary code. An additional issue in argument parsing allows denial of service.

Alerts:
CentOS CESA-2013:0521 pam 2013年03月09日
Scientific Linux SL-pam-20130228 pam 2013年02月28日
Oracle ELSA-2013-0521 pam 2013年02月25日
Red Hat RHSA-2013:0521-02 pam 2013年02月21日
Gentoo 201206-31 pam 2012年06月25日
Fedora FEDORA-2011-16365 pam 2011年11月25日
Fedora FEDORA-2011-16390 pam 2011年12月04日
SUSE SUSE-SU-2011:1218-1 pam 2011年11月04日
SUSE SUSE-SU-2011:1207-1 pam 2011年11月03日
SUSE SUSE-SU-2011:1205-1 pam 2011年11月03日
SUSE SUSE-SU-2011:1209-1 pam 2011年11月03日
openSUSE openSUSE-SU-2011:1204-1 pam 2011年11月03日
openSUSE openSUSE-SU-2011:1208-1 pam 2011年11月03日
Ubuntu USN-1237-1 pam 2011年10月24日
Debian DSA-2326-1 pam 2011年10月24日

to post comments

(追記) (追記ここまで)

Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds

AltStyle によって変換されたページ (->オリジナル) /