vendor:
OpenPAM
by:
Anonymous
7.5
CVSS
HIGH
Local privilege-escalation
264
CWE
Product Name: OpenPAM
Affected Version From: Not specified
Affected Version To: Not specified
Patch Exists: YES
Related CWE:
CPE: Not specified
Platforms Tested: FreeBSD 8.1 (Not tested on Linux)
2011
Local privilege-escalation vulnerability in OpenPAM
The vulnerability allows local attackers to execute arbitrary code with superuser privileges by exploiting a flaw in the 'pam_start()' function in OpenPAM. This can lead to the complete compromise of affected computers.
Mitigation:
Apply the patch provided in the link mentioned in the script.