Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-2516
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-2516

Description:
pam_sm_authenticate in pam_pgsql.c in libpam-pgsql 0.6.3 does not properly consider operator precedence when evaluating the success of a pam_get_pass function call, which allows local users to gain privileges via a SIGINT signal when this function is executing, as demonstrated by a CTRL-C sequence at a sudo password prompt in an "auth sufficient pam_pgsql.so" configuration.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/42653

ST
  1020111

SAID
  Secunia Advisory: SA30391

CONFIRM
  http://sourceforge.net/project/shownotes.php?release_id=601775
  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=481970

BID
  29360


Return to the previous page.