Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2017-12197
HistoryJan 18, 2018 - 9:29 p.m.

CVE-2017-12197

2018-01-1821:29:00
Debian Security Bug Tracker
security-tracker.debian.org
6

EPSS

0.002

Percentile

57.5%

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.

OSVersionArchitecturePackageVersionFilename
Debian9alllibpam4j< 1.4-2+deb9u1libpam4j_1.4-2+deb9u1_all.deb