漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
pam_usb: Infinite loop DoS in process-tree walk when parent process exits during authentication
Vulnerability Description
pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_parent_id() can cause an infinite loop DoS because it does not initialize *ppid on failure. In pusb_local_login(), the same variable is reused as input and output in a process-tree while loop; if /proc/<pid>/stat cannot be read (for example, when an ancestor process exits during authentication), the PID is not updated and the loop does not terminate. This hangs the authenticating process (such as sudo, sshd, or login) until it is forcibly terminated. This issue has been fixed in version 0.9.2.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不可达退出条件的循环(无限循环)
Vulnerability Title
mcdope pam_usb 资源管理错误漏洞
Vulnerability Description
mcdope pam_usb是mcdope的认证模块。 mcdope pam_usb 0.9.1及之前版本存在资源管理错误漏洞,该漏洞源于usb_get_process_parent_id()在失败时未初始化*ppid,且pusb_local_login()中同一变量在进程树while循环中被重复使用作为输入和输出,若无法读取/proc/<pid>/stat则PID不更新且循环不终止,可能导致无限循环拒绝服务攻击。
CVSS Information
N/A
Vulnerability Type
N/A