CVE-2011-4122

OpenPAM <r478 - Privilege Escalation

Title source: llm

Description

Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass.

Exploits (1)

exploitdb WORKING POC VERIFIED
by IKCE · perllocalbsd
https://www.exploit-db.com/exploits/36296

Scores

EPSS 0.0037
EPSS Percentile 59.1%

Details

CWE
CWE-22
Status published
Products (1)
freebsd/freebsd 8.1
Published Nov 17, 2011
Tracked Since Feb 18, 2026