First published: Thu Nov 17 2011(Updated: )
Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD FreeBSD | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.