HIGH · 7.5

CVE-2005-2949

pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses the same subrequest handle, which allows remote attackers or local users to login as other use...

Vulnerability Description

pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses the same subrequest handle, which allows remote attackers or local users to login as other users by using certain applications that allow the username to be changed during authentication, such as /bin/login.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Mark D. RothPam Per User0.1

References

FAQ

What is CVE-2005-2949?

CVE-2005-2949 is a vulnerability with a CVSS score of 7.5 (HIGH). pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses the same subrequest handle, which allows remote attackers or local users to login as other use...

How severe is CVE-2005-2949?

CVE-2005-2949 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-2949?

Check the references section above for vendor advisories and patch information. Affected products include: Mark D. Roth Pam Per User.