Back

CVE-2003-0672

Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled when recording a log message.

Published: Aug 27, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
leon_j_breedt pam-pgsql 0.5.1
leon_j_breedt pam-pgsql 0.5.2

GitHub Security Advisory GHSA-xwrx-9qxp-9w34

Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute...

References (2)

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.06%

Top 14% most likely to be exploited

Threat Score 30.9 / 100

Data Sources

NVD EPSS GitHub