CVE detail
CVE-2010-4341 — CVE-2010-4341
Published 2011-01-25 · Modified 2026-06-16 · Vendor fedorahosted · Product sssd · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0049
EPSS probability
exploitation probability, 30d
39.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loop, crash, and login prevention) via a crafted packet.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References