CVE-2001-1147 describes a critical vulnerability in the PAM implementation of /bin/login within the util-linux package (versions prior to 2.11). This flaw allows password entries to be inadvertently shared between different users across multiple PAM calls, potentially exposing credentials. With a CVSS score of 7.2 (HIGH), it carries a significant risk of complete confidentiality, integrity, and availability compromise, requiring local access but with low attack complexity. Despite its age and high community discussion (10 mentions), there is no evidence of active exploitation, nor are there known public exploits in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.10sCPE matchmatch criteria | cpe:2.3:a:andries_brouwer:util-linux:2.10s:*:*:*:*:*:*:* | ||
2.11fCPE matchmatch criteria | cpe:2.3:a:andries_brouwer:util-linux:2.11f:*:*:*:*:*:*:* | ||
2.11hCPE matchmatch criteria | cpe:2.3:a:andries_brouwer:util-linux:2.11h:*:*:*:*:*:*:* | ||
2.11iCPE matchmatch criteria | cpe:2.3:a:andries_brouwer:util-linux:2.11i:*:*:*:*:*:*:* | ||
2.11kCPE matchmatch criteria | cpe:2.3:a:andries_brouwer:util-linux:2.11k:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.