Back

MEDIUM

(pam_env): Stack-based buffer overflow by parsing user's pam_environment file

Published Jul 22, 2012

Description

Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long string of white spaces at the beginning of the ~/.pam_environment file.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of pam package as shipped with Red Hat Enterprise Linux 5.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 22, 2012
Updated Aug 6, 2024
Reserved Aug 16, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Oct 24, 2011