7.2

CVE-2007-0003

pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Andrew MorganLinux Pam Version0.99.7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.31
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.novell.com/linux/security/advisories/2007_3_sr.html
http://osvdb.org/32017
http://secunia.com/advisories/23858
http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01271.html
Vendor Advisory
http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01277.html
Vendor Advisory
http://www.securityfocus.com/bid/22204
http://www.vupen.com/english/advisories/2007/0323
https://exchange.xforce.ibmcloud.com/vulnerabilities/31739
https://www.redhat.com/archives/pam-list/2007-January/msg00017.html
Vendor Advisory