Lucene search

K
cve[email protected]CVE-2006-0056
HistoryFeb 13, 2006 - 11:06 a.m.

CVE-2006-0056

2006-02-1311:06:00
CWE-119
web.nvd.nist.gov
22
cve-2006-0056
pam-mysql
authentication
double free
vulnerability
denial of service
application crash
arbitrary code
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.319 Low

EPSS

Percentile

97.0%

Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function. NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL.

Affected configurations

NVD
Node
pam-mysqlpam-mysqlMatch0.1
OR
pam-mysqlpam-mysqlMatch0.2
OR
pam-mysqlpam-mysqlMatch0.3
OR
pam-mysqlpam-mysqlMatch0.4
OR
pam-mysqlpam-mysqlMatch0.4.7
OR
pam-mysqlpam-mysqlMatch0.5
OR
pam-mysqlpam-mysqlMatch0.6
OR
pam-mysqlpam-mysqlMatch0.7_pre1
OR
pam-mysqlpam-mysqlMatch0.7_pre2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.319 Low

EPSS

Percentile

97.0%