An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.
2020-10-26T12:17:12.693
2024-11-21T05:21:38.873
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | illumos | illumos | < 2020-10-22 | Yes |
Operating System | joyent | smartos | < 20201022 | Yes |
Operating System | omniosce | omnios | < r151030by | Yes |
Operating System | omniosce | omnios | ≤ r151032ay | Yes |
Operating System | omniosce | omnios | < r151034y | Yes |