Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2003-0388

EPSS 0.15% · P36
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2003-0388

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux-PAM getlogin()可被欺骗漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Pluggable Authentication Module (PAM)是用于验证用户的机制。使用在多种Linux版本上。 Linux-PAM中的pam_wheel没有安全地使用getlogin()函数,本地攻击者可以利用这个漏洞有可能绕过部分限制,无需密码获得root用户权限。 pam_wheel模块一般结合su(1)允许属于可信组的用户无需密码使用部分命令。此模块利用getlogin()函数判断当前登录用户名,获取的用户名然后与配置文件中指定的可信组列表成员进行比较,下面是部分代码: fromsu
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2003-0388

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2003-0388

Please Login to view more intelligence information

Same Patch Batch · n/a · 2003-06-18 · 15 CVEs total

CVE-2001-1409XFree86 Dexconf Dev/Dri目录权限不安全漏洞
CVE-2003-0359NetHack / JNetHack不正确权限漏洞
CVE-2003-0366Lyskom服务程序未授权用户远程拒绝服务攻击漏洞
CVE-2003-0379Apple AFP Server任意文件破坏漏洞
CVE-2003-0418Linux内核IP堆栈错误响应漏洞
CVE-2003-0419SMC无线路由器畸形PPTP包远程拒绝服务攻击漏洞
CVE-2003-0428Ethereal DCERPC解析器内存分配漏洞
CVE-2003-0429Ethereal OSI解析器缓冲区溢出漏洞
CVE-2003-0430Ethereal SPNEGO解析器远程拒绝服务攻击漏洞
CVE-2003-0431Ethereal TVB_GET_NSTRINGZ0()内存处理漏洞
CVE-2003-0432Ethereal多个解析器字符串处理漏洞
CVE-2003-0433Gnocatan Server多个远程缓冲区溢出漏洞
CVE-2003-0434多家PDF厂商超链接任意命令执行漏洞
CVE-2003-0435Typespeed远程内存破坏漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2003-0388

No comments yet


Leave a comment