Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24161
HistoryApr 10, 2020 - 12:47 a.m.

Denial Of Service (DoS)

2020-04-1000:47:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.0004 Low

EPSS

Percentile

5.1%

Pluggable Authentication Modules (PAM) is vulnerable to Denial of Service (DoS). The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.