Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24159
HistoryApr 10, 2020 - 12:47 a.m.

Information Disclosure

2020-04-1000:47:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.0004 Low

EPSS

Percentile

10.1%

Pluggable Authentication Modules (PAM) is vulnerable to Information Disclosure. It was discovered that the pam_mail module used root privileges while accessing users’ files. In certain configurations, a local, unprivileged user could use this flaw to obtain limited information about files or directories that they do not have access to.

References