CVE-2013-0191

Lucas Clemente Vella Libpam-pgsql - Authentication Bypass

Title source: rule

Description

libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allows remote attackers to bypass authentication via a crafted password.

Scores

EPSS 0.0100
EPSS Percentile 76.7%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

lucas_clemente_vella/libpam-pgsql

Timeline

Published Jun 03, 2014
Tracked Since Feb 18, 2026