First published: Wed Jun 18 2003(Updated: )
pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux-PAM | <=0.77 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0388 is considered to have a medium severity due to its ability to allow local users to spoof log entries and gain privileges.
To fix CVE-2003-0388, ensure that the trust option is disabled and the use_uid option is enabled in the pam_wheel configuration.
CVE-2003-0388 affects systems using Linux-PAM version 0.78 or earlier with specific pam_wheel settings configured.
The impact of CVE-2003-0388 includes potential unauthorized privilege escalation through the spoofing of log entries.
CVE-2003-0388 may still pose a threat on outdated systems or in environments that have not applied necessary patches.