Information disclosure in linux-pam - CVE-2015-3238

 

Information disclosure in linux-pam - CVE-2015-3238

Published: August 24, 2015 / Updated: July 28, 2020


Vulnerability identifier: #VU32409
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3238
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.

The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.


Affected software

linux-pam
Amazon Linux AMI
Fedora
linux-pam (Alpine package)
pam
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000
IBM SAN Volume Controller

How to mitigate CVE-2015-3238

Install update from vendor's website.

linux-pam - update to 1.2.1
linux-pam (Alpine package) - update to 1.2.1-r0
pam - addressed in versions 1.1.8-19.fc21, 1.1.8-19.fc22
IBM Storwize V3500 - addressed in versions 7.4.0.8, 7.5.0.6, 7.6.0.3
IBM Storwize V3700 - addressed in versions 7.4.0.8, 7.5.0.6, 7.6.0.3
IBM Storwize V5000 - addressed in versions 7.4.0.8, 7.5.0.6, 7.6.0.3
IBM Storwize V7000 - addressed in versions 7.4.0.8, 7.5.0.6, 7.6.0.3
IBM SAN Volume Controller - addressed in versions 7.4.0.8, 7.5.0.6, 7.6.0.3

External References

Related Security Bulletins