CVE-2020-27678 is a critical buffer overflow vulnerability found in the parse_user_name function within libpam/pam_framework.c of illumos-based operating systems, including OmniOS and SmartOS, prior to specific patch levels. This flaw allows for unauthenticated remote attackers to achieve complete compromise of confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8. Despite its high severity, there is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020-10-22CPE matchmatch criteria | cpe:2.3:o:illumos:illumos:*:*:*:*:*:*:*:* | ||
< 20201022CPE matchmatch criteria | cpe:2.3:o:joyent:smartos:*:*:*:*:*:*:*:* | ||
< r151030byCPE matchmatch criteria | cpe:2.3:o:omniosce:omnios:*:*:*:*:community:*:*:* | ||
>= r151032, <= r151032ayCPE matchmatch criteria | cpe:2.3:o:omniosce:omnios:*:*:*:*:community:*:*:* | ||
>= r151034, < r151034yCPE matchmatch criteria | cpe:2.3:o:omniosce:omnios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.