摘要:
A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn t exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.
安全等级: Low
公告ID: KylinSec-SA-2022-1625
发布日期: 2022年7月15日
关联CVE: CVE-2020-27780
A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn t exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2020-27780 | KY3.4-4A | pam | Unaffected |
CVE-2020-27780 | KY3.4-5 | pam | Unaffected |
CVE-2020-27780 | KY3.5.1 | pam | Unaffected |