CVE-2011-3172: unix2_chkpwd do not check for a valid account
Published Jun 8, 2018
·Updated
A vulnerability in pammodules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.
Affected Software
1 affected component
SUSE SUSE Linux Enterprise Server<12.0
Event History
Jun 8, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2011-3172.
2
What is the severity level of CVE-2011-3172?
CVE-2011-3172 has a severity level of critical (9.8).
3
Which software is affected by CVE-2011-3172?
CVE-2011-3172 affects SUSE Linux Enterprise version prior to 12.
4
How does CVE-2011-3172 allow attackers to gain unauthorized access?
CVE-2011-3172 allows attackers to log into accounts that should have been disabled.
5
Is there a fix available for CVE-2011-3172?
Yes, a fix is available. Refer to the provided references for more information.