CVE Feed

    Dashboard / CVE / CVE-2011-5054

    CVE-2011-5054

    kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any configured PAM stack, and possibly trigger unintended side effects, via an arbitrary valid PAM service name, a different vulnerability than CVE-2011-4122. NOTE: the vendor indicates that the possibility of resultant privilege escalation may be "a bit far-fetched."

    Published:Jan 6, 2012
    Last Modified:Apr 11, 2025
    EPS:Jan 6, 2012
    EPSS Score:0.00039
    CVSS Score:6.9

    Affected Products

    Vendor
    Kde
    Product
    Kcheckpass

    Exploits

    No exploit reference

    Common Weakness Enumeration

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High