CVE-2001-1147: High severity Andries Brouwer Util-linux vulnerability
The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a different user, when used in certain PAM modules such as pamlimits.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1147?
CVE-2001-1147 is considered a high severity vulnerability due to its potential impact on user credential exposure.
How do I fix CVE-2001-1147?
To fix CVE-2001-1147, update the util-linux package to version 2.11l or newer.
Which applications are affected by CVE-2001-1147?
CVE-2001-1147 affects the PAM implementation in the /bin/login of the util-linux package before version 2.11l.
What operating systems are impacted by CVE-2001-1147?
CVE-2001-1147 primarily impacts Unix-like operating systems that utilize the vulnerable versions of the util-linux package.
Can CVE-2001-1147 lead to unauthorized access?
Yes, CVE-2001-1147 can potentially allow one user to access another user's credentials, posing a significant security risk.