CVE-2001-1147
Last modified
CVE-2001-1147 is a vulnerability of currently unknown severity. The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a different user, when used in certain PAM modules such as pam_limits.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a different user, when used in certain PAM modules such as pam_limits.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Andries Brouwer | Util-Linux | 2.10s |
| Andries Brouwer | Util-Linux | 2.11f |
| Andries Brouwer | Util-Linux | 2.11h |
| Andries Brouwer | Util-Linux | 2.11i |
| Andries Brouwer | Util-Linux | 2.11k |
References
- http://www.iss.net/security_center/static/7266.phpPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/219175Vendor Advisory
- http://www.securityfocus.com/bid/3415Patch, Vendor Advisory
- http://www.iss.net/security_center/static/7266.phpPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/219175Vendor Advisory
- http://www.securityfocus.com/bid/3415Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1147?
How severe is CVE-2001-1147?
How do I fix CVE-2001-1147?
Are you affected by CVE-2001-1147?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
