Vulnerability Name: | CVE-2000-0378 (CCN-4869) | ||||||||
Assigned: | 2000-05-02 | ||||||||
Published: | 2000-05-02 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20000502 pam_console bug Source: CCN Type: BugTraq Mailing List, Tue May 02 2000 - 15:23:44 CDT pam_console bug Source: MITRE Type: CNA CVE-2000-0378 Source: CCN Type: OSVDB ID: 1315 Multiple Linux Vendor pam_console Persistent Open File Descriptor Information Disclosure Source: BID Type: UNKNOWN 1176 Source: CCN Type: BID-1176 Multiple Linux Vendor pam_console Vulnerability Source: XF Type: UNKNOWN linux-pam-sniff-activities(4869) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |