CVE-2015-3238: Linux-Pam
Medium severity, CVSS 6.5. EPSS: 2.7% chance of exploitation in the next 30 days.
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
Affected products
- Linux-Pam Linux-Pam: up to and including 1.1.8
- Oracle Sparc-Opl Service Processor: up to and including 1121
Published 2015-08-24. Last modified 2026-06-17.