Unrated severityNVD Advisory· Published Jun 3, 2014· Updated May 6, 2026
CVE-2013-0191
CVE-2013-0191
Description
libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allows remote attackers to bypass authentication via a crafted password.
Affected products
1- cpe:2.3:a:lucas_clemente_vella:libpam-pgsql:0.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- sourceforge.net/u/lvella/pam-pgsql/ci/9361f5970e5dd90a747319995b67c2f73b91448c/nvdExploitPatch
- lists.opensuse.org/opensuse-security-announce/2016-08/msg00010.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-08/msg00040.htmlnvd
- seclists.org/oss-sec/2013/q1/86nvd
- seclists.org/oss-sec/2013/q1/99nvd
- sourceforge.net/p/pam-pgsql/bugs/13/nvd
- www.securityfocus.com/bid/57440nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/81363nvd
News mentions
0No linked articles in our index yet.