REDHAT-BUG-1038555: Low severity Linux-PAM pam_userdb vulnerability

Published Dec 5, 2013
·
Updated

It was found that in pamuserdb module for PAM, password hashes weren't compared case-sensitively, which could lead to acceptance of hashes for completely different passwords, which shouldn't be accepted.

After hashing the user's password with crypt(), pamuserdb compares the result to the stored hash case-insensitively with strncasecmp(), which should be avoided, as it could result in an increased possibility of a successful brute-force attack.

References: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731368

Affected Software

1 affected component
Linux-PAM pam_userdb

Event History

Dec 5, 2013
Data Sourced
via Red Hat·10:40 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1038555?

The severity of REDHAT-BUG-1038555 is considered high due to the potential for unauthorized access.

2

How do I fix REDHAT-BUG-1038555?

To fix REDHAT-BUG-1038555, you should update the pam_userdb module to a version where case-sensitive password hashing is correctly implemented.

3

What versions of pam_userdb are affected by REDHAT-BUG-1038555?

Versions of pam_userdb prior to the security patch addressing REDHAT-BUG-1038555 are affected.

4

What are the implications of REDHAT-BUG-1038555?

The implications of REDHAT-BUG-1038555 include a security risk that allows for the acceptance of incorrect password hashes.

5

Is there a workaround for REDHAT-BUG-1038555?

Currently, there is no official workaround for REDHAT-BUG-1038555; updating to the patched version is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203