CVE-2000-0378

Linux pam_console - Info Disclosure

Title source: llm
STIX 2.1

Description

The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Michal Zalewski · clocallinux
https://www.exploit-db.com/exploits/19900

Scores

EPSS 0.0095
EPSS Percentile 76.4%

Details

Status published
Products (3)
redhat/linux 6.0
redhat/linux 6.1
redhat/linux 6.2
Published May 03, 2000
Tracked Since Feb 18, 2026