CVE-2001-1147
Published Oct 8, 2001
Last updated 16 years ago
Overview
- Description
- The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a different user, when used in certain PAM modules such as pam_limits.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:andries_brouwer:util-linux:2.10s:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "861DAF15-48B3-42C0-B747-76967AE1918D" }, { "criteria": "cpe:2.3:a:andries_brouwer:util-linux:2.11f:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE56638F-4097-4754-80A8-88EC5DAB132A" }, { "criteria": "cpe:2.3:a:andries_brouwer:util-linux:2.11h:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3324A111-D5BC-4A81-8EF4-2E95AFAFD19D" }, { "criteria": "cpe:2.3:a:andries_brouwer:util-linux:2.11i:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F256A5F-8525-452F-BF47-8F916A65608C" }, { "criteria": "cpe:2.3:a:andries_brouwer:util-linux:2.11k:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9A6AEAFC-F3AA-46CF-81CD-3CE5151CFC62" } ], "operator": "OR" } ] } ]