|
|
|
![]() |
Vulnerability Note VU#693909PAM-MySQL contains a double-free vulnerabilityOverviewPAM-MySQL contains a double-free vulnerability that may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.I. DescriptionPAM-MySQL provides a Pluggable Authentication Module (PAM) interface to a MySQL database. PAM-MySQL does not securely handle a pointer returned by the pam_get_item() routine, which results in a double-free vulnerability. The vulnerability exists if the following conditions are present:
II. ImpactIf a remote attacker supplies a specially crafted password to a vulnerable PAM-MySQL installation, that attacker may be able to crash the PAM-MySQL process. Note that it may be possible to exploit this vulnerability to execute arbitrary code.III. SolutionUpgrade PAM-MySQLUpgrading to PAM-MySQL version 0.6.2 or PAM-MySQL version 0.7pre3 will correct this issue.
References
This vulnerability was reported by Moriyoshi Koizumi. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||