Debian Security Advisory DSA 374-1 (libpam-smb)

Published: 2008-01-17 21:36:24
CVE Author: NIST National Vulnerability Database (NVD)

CVSS Base Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Recommendations:
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20374-1

Technical Details:
libpam-smb is a PAM authentication module which makes it possible to authenticate users against a password database managed by Samba or a Microsoft Windows server. If a long password is supplied, this can cause a buffer overflow which could be exploited to execute arbitrary code with the privileges of the process which invokes PAM services. For the stable distribution (woody) this problem has been fixed in version 1.1.6-1.1woody1. For the unstable distribution (sid) does not contain a libpam-smb Linux Distribution Package. We recommend that you update your libpam-smb Linux Distribution Package.

Summary:
The remote host is missing an update to libpam-smb announced via advisory DSA 374-1.

Detection Type:
Linux Distribution Package

Solution Type:
Vendor Patch

NIST (National Institute of Standards and Technology) NVD (National Vulnerability Database)

https://nvd.nist.gov/vuln/detail/CVE-2003-0686

Search
Severity
High
CVSS Score
7.5

You never have to pay for a vulnerability scanning and management software again.

Tired of paying a subscription 'per asset' or 'per IP'? Well you can officially cancel your current subscription. Mageni provides a free, open source and enterprise-ready vulnerability scanning and management platform which helps you to find, prioritize, remediate and manage your vulnerabilities. It is free and always will be.