Local Denial of Service in SSSD PAM Responder by Red Hat
CVE-2010-4341

Currently unrated

Key Information:

Status
Vendor
CVE Published:
25 January 2011

What is CVE-2010-4341?

The pam_parse_in_data_v2 function within the PAM responder in SSSD versions 1.5.0, 1.4.x, and 1.3 is susceptible to a denial of service attack. Local users can exploit this vulnerability by sending crafted packets that can lead to an infinite loop, causing application crashes and preventing user logins. This issue can significantly disrupt service availability, emphasizing the need for prompt patch management and system monitoring.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.