CVE-2005-2977
EPSS 0.08%
Description
The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_chkpwd, which does not log failed guesses or delay its responses.
How to fix CVE-2005-2977
To remediate CVE-2005-2977, upgrade the affected package to a fixed version below.
- Debian/pam—upgrade to 0.99.7.1-2 or later
Is CVE-2005-2977 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.99.7.1-2