Back

MEDIUM

pam: integer signedness error in _pam_StrTok()

Published Mar 12, 2009

Description

Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this issue to be a security vulnerability. Affected function is only used to parse PAM configuration files and this bug can only be triggered by specific configuration created by the system administrator.

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 12, 2009
Updated Aug 7, 2024
Reserved Mar 12, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Feb 25, 2009