CVE-2020-27678: Buffer Overflow
Published Oct 23, 2020
·Updated
An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parseusername in lib/libpam/pamframework.c.
Affected Software
5 affected components
illumos Illumos<2020-10-22
Joyent SmartOS<20201022
Omniosce Omnios<r151030by
Omniosce Omnios>=r151032<=r151032ay
Omniosce Omnios>=r151034<r151034y
Remediation
Event History
Oct 23, 2020
CVE Published
via MITRE·08:25 PM
Data Sourced
via MITRE·08:25 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-27678.
2
What is the severity of CVE-2020-27678?
The severity of CVE-2020-27678 is critical with a score of 9.8.
3
Which software versions are affected by CVE-2020-27678?
CVE-2020-27678 affects illumos versions before 2020-10-22, OmniOS versions before r151030by, r151032ay, r151034y, and SmartOS versions before 20201022.
4
What is the description of CVE-2020-27678?
CVE-2020-27678 is a buffer overflow vulnerability in parse_user_name in lib/libpam/pam_framework.c.
5
Is there a fix available for CVE-2020-27678?
Yes, a fix for CVE-2020-27678 is available. Please refer to the provided reference for more information.