CVE-2015-3238

NameCVE-2015-3238
DescriptionThe _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs789986

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pam (PTS)jessie1.1.8-3.1+deb8u2fixed
stretch1.1.8-3.6fixed
bullseye, sid, buster1.3.1-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pamsource(unstable)1.1.8-3.2medium789986
pamsourcejessie1.1.8-3.1+deb8u1medium

Notes

[wheezy] - pam <no-dsa> (Minor issue e.g. in combination with enabled SELinux)
[squeeze] - pam <no-dsa> (Minor issue e.g. in combination with enabled SELinux)
https://git.fedorahosted.org/cgit/linux-pam.git/commit/?id=e89d4c97385ff8180e6e81e84c5aa745daf28a79
https://www.redhat.com/archives/pam-list/2015-June/msg00001.html

Search for package or bug name: Reporting problems