CVE-2020-27678

An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
illumosillumos
𝑥
< 2020-10-22
joyentsmartos
𝑥
< 20201022
omniosceomnios
𝑥
< r151030by
omniosceomnios
r151032 ≤
𝑥
≤ r151032ay
omniosceomnios
r151034 ≤
𝑥
< r151034y
𝑥
= Vulnerable software versions