Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-7041
HistoryMay 08, 2014 - 12:00 a.m.

CVE-2013-7041

2014-05-0800:00:00
ubuntu.com
ubuntu.com
15

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

71.5%

The pam_userdb module for Pam uses a case-insensitive method to compare
hashed passwords, which makes it easier for attackers to guess the password
via a brute force attack.

Bugs

Notes

Author Note
mdeslaur see additional comments in oss-security thread
OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchpam< 1.1.3-7ubuntu2.1UNKNOWN
ubuntu14.04noarchpam< 1.1.8-1ubuntu2.1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

71.5%