Search CVE reports


Toggle filters

71 – 80 of 89 results


CVE-2009-0360

Medium priority

Some fixes available 4 of 6

Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified...

1 affected package

libpam-krb5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-krb5
Show less packages

CVE-2008-5138

Low priority
Ignored

passwdehd in libpam-mount 0.43 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/passwdehd.##### temporary file.

1 affected package

libpam-mount

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-mount
Show less packages

CVE-2008-3825

Medium priority
Not affected

pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when reading a Kerberos credential cache, which allows local users to gain privileges...

1 affected package

libpam-krb5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-krb5
Show less packages

CVE-2008-3970

Low priority
Ignored

pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount.

1 affected package

libpam-mount

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-mount
Show less packages

CVE-2008-2516

Medium priority

Some fixes available 5 of 7

pam_sm_authenticate in pam_pgsql.c in libpam-pgsql 0.6.3 does not properly consider operator precedence when evaluating the success of a pam_get_pass function call, which allows local users to gain privileges via a SIGINT signal...

1 affected package

pam-pgsql

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam-pgsql
Show less packages

CVE-2007-6418

Medium priority
Fixed

The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments.

1 affected package

dspam

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dspam
Show less packages

CVE-2007-2873

Medium priority

Some fixes available 5 of 8

SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack...

1 affected package

spamassassin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin
Show less packages

CVE-2007-0451

Medium priority

Some fixes available 6 of 8

Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."

1 affected package

spamassassin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin
Show less packages

CVE-2007-0844

Medium priority
Not affected

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank...

1 affected package

libpam-ssh

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-ssh
Show less packages

CVE-2007-0003

Medium priority
Not affected

pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.

1 affected package

pam

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam
Show less packages