CVE-2011-4122
OpenPAM <r478 - Privilege Escalation
Title source: llmDescription
Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass.
Exploits (1)
References (9)
Scores
EPSS
0.0037
EPSS Percentile
59.1%
Details
CWE
CWE-22
Status
published
Products (1)
freebsd/freebsd
8.1
Published
Nov 17, 2011
Tracked Since
Feb 18, 2026