CVE-2014-2583
CVE-2014-2583 is a medium-severity vulnerability in Linux-pam with a CVSS 2.0 base score of 5.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 2.0 base score 5.8)
- EPSS exploit prediction: 4% (90th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-22
- Affected product: Linux-pam
- Published:
- Last modified:
Description
Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.
Frequently asked questions
- What is CVE-2014-2583?
- Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.
- How severe is CVE-2014-2583?
- CVE-2014-2583 has a CVSS 2.0 base score of 5.8, rated medium severity.
- Is CVE-2014-2583 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 4% (90th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2014-2583?
- CVE-2014-2583 affects Linux-pam. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2014-2583?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2014-2583 published?
- CVE-2014-2583 was published on 2014-04-10 and last updated on 2026-06-17.
References
- http://secunia.com/advisories/57317
- http://www.openwall.com/lists/oss-security/2014/03/24/5
- http://www.openwall.com/lists/oss-security/2014/03/26/10
- http://www.openwall.com/lists/oss-security/2014/03/31/6
- http://www.securityfocus.com/bid/66493
- http://www.ubuntu.com/usn/USN-2935-1
- http://www.ubuntu.com/usn/USN-2935-2
- http://www.ubuntu.com/usn/USN-2935-3
- https://git.fedorahosted.org/cgit/linux-pam.git/commit/?id=Linux-PAM-1_1_8-32-g9dcead8
- https://security.gentoo.org/glsa/201605-05
Affected products (1)
- cpe:2.3:a:linux-pam:linux-pam:1.1.8:*:*:*:*:*:*:*
More vulnerabilities in Linux-pam
- CVE-2022-28321 — Critical (CVSS 9.8): The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The…
- CVE-2020-27780 — Critical (CVSS 9.8): A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users.…
- CVE-2010-4708 — High (CVSS 7.2): The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory,…
- CVE-2010-3853 — Medium (CVSS 6.9): pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking…
- CVE-2009-0887 — Medium (CVSS 6.6): Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier,…
- CVE-2015-3238 — Medium (CVSS 6.5): The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to…
All CVEs affecting Linux-pam →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.