Beveiligingsadvies

CVE-2011-3149

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2012-07-22 17:00:00
Laatst bijgewerkt 2024-08-06 23:22:27
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial of service (CPU consumption).