CVE-2011-4122
Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass.
- Affected products
- Openam
- Freebsd
- = 8.1
- Fix
- Available
- CVSS 2.0
- 6.9 MEDIUM
- EPSS
- 0.9% (57th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2011-11-17
CVE-2011-4122 at NVD
1 known exploit for CVE-2011-4122
Proof-of-concept code and exploit modules indexed by Sploitus