Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled when recording a log message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pam-PGSQL用户名记录远程格式串处理漏洞
Vulnerability Description
pam-pgsql是一款用于PostgreSQL数据库接口的PAM认证模块。 pam-pgsql不正确处理用户提交的用户名,当记录消息时可导致发生格式字符串问题。 攻击者提交恶意格式字符串作为用户名给使用PAM验证的程序(如HTTP、SSH、telnet),用户名在随后的pam-pqsql记录日志的过程中会发生格式串处理问题,导致进程内存中的敏感信息被破坏 ,精心构建提交数据可能以使用PAM验证的进程权限在系统上执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A