CVE-2015-3238: Linux-Pam

Medium severity, CVSS 6.5. EPSS: 2.7% chance of exploitation in the next 30 days.

The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.

Affected products

  • Linux-Pam Linux-Pam: up to and including 1.1.8
  • Oracle Sparc-Opl Service Processor: up to and including 1121

Published 2015-08-24. Last modified 2026-06-17.