Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pam‘pam_userdb’模块加密问题漏洞
Vulnerability Description
PAM(也称Linux-PAM)是一种用于Linux平台中的认证机制。pam_userdb是其中的一个认证模块,主要通过一个轻量级的Berkeley数据库来保存用户和口令信息。 Pam pam_userdb模块存在加密问题漏洞,该漏洞源于比较哈希密码使用‘case-insensitive’方法。攻击者可通过实施暴力破解攻击利用该漏洞猜出密码。
CVSS Information
N/A
Vulnerability Type
N/A