Logo
componentlinux-pam
Name
linux-pam
Version
1.7.2
Type
library
Description
-
Licenses
BSD-3-Clause
PURL
-
CPE
cpe:2.3:a:linux-pam:linux-pam:1.7.2:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
2025.02.x
1.6.1

Vulnerabilities#


Name
Analysis
Description
Exploitable
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.