← Back to CVE List

CVE-2014-3879

Published: 2020-02-18T17:15Z
Last Modified: 2024-11-21T02:09Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass authentication via a login (1) without a password or (2) with an incorrect password. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt