CVE-2015-3238
MEDIUMLinux-PAM <1.2.1 - DoS/Info Disclosure
Title source: llmDescription
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
References (13)
Scores
CVSS v3
6.5
EPSS
0.0361
EPSS Percentile
87.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Classification
CWE
CWE-200
Status
draft
Affected Products (2)
linux-pam/linux-pam
< 1.1.8
oracle/sparc-opl_service_processor
< 1121
Timeline
Published
Aug 24, 2015
Tracked Since
Feb 18, 2026