CVE-2009-0887

EUVD-2009-0884
Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.6 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:S/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
Affected Products (NVD)
VendorProductVersion
linux-pamlinux-pam
𝑥
≤ 1.0.3
linux-pamlinux-pam
0.99.1.0
linux-pamlinux-pam
0.99.2.0
linux-pamlinux-pam
0.99.2.1
linux-pamlinux-pam
0.99.3.0
linux-pamlinux-pam
0.99.4.0
linux-pamlinux-pam
0.99.5.0
linux-pamlinux-pam
0.99.6.0
linux-pamlinux-pam
0.99.6.1
linux-pamlinux-pam
0.99.6.2
linux-pamlinux-pam
0.99.6.3
linux-pamlinux-pam
0.99.7.0
linux-pamlinux-pam
0.99.7.1
linux-pamlinux-pam
0.99.8.0
linux-pamlinux-pam
0.99.8.1
linux-pamlinux-pam
0.99.9.0
linux-pamlinux-pam
0.99.10.0
linux-pamlinux-pam
1.0.0
linux-pamlinux-pam
1.0.1
linux-pamlinux-pam
1.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pam
bookworm
1.5.2-6+deb12u1
fixed
bullseye
1.4.0-9+deb11u1
fixed
sid
1.5.3-7
fixed
trixie
1.5.3-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pam
dapper
ignored
gutsy
ignored
hardy
Fixed 0.99.7.1-5ubuntu6.3
released
intrepid
ignored
jaunty
ignored
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
not-affected
Common Weakness Enumeration