First published: Mon Oct 28 2002(Updated: )
PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pam Extern | =0.76 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1227 is considered a critical vulnerability due to its potential to allow unauthorized privileged access.
To fix CVE-2002-1227, upgrade to a patched version of PAM that addresses this security issue.
CVE-2002-1227 specifically affects PAM version 0.76.
Yes, CVE-2002-1227 can be exploited by both local and remote attackers.
CVE-2002-1227 allows attackers to gain privileges as users whose accounts have been disabled.