{"id":"CVE-2020-27780","details":"A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.","modified":"2026-08-07T15:12:38.039889Z","published":"2020-12-18T00:15:14.330Z","related":["openSUSE-SU-2024:11140-1"],"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1901094"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/linux-pam/linux-pam","events":[{"introduced":"62d826471e87e27b39a36ccbeee58999e2514a92"},{"fixed":"225f17470eed9f44282f435ad1ed64c94d9a2ddf"}],"database_specific":{"cpe":"cpe:2.3:a:linux-pam:linux-pam:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.5.0"},{"fixed":"1.5.1"}],"source":"CPE_RANGE"}}],"versions":["v1.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-27780.json","vanir_signatures_modified":"2026-08-07T15:12:38Z","vanir_signatures":[{"id":"CVE-2020-27780-90a0a465","signature_type":"Line","signature_version":"v1","source":"https://github.com/linux-pam/linux-pam/commit/225f17470eed9f44282f435ad1ed64c94d9a2ddf","target":{"file":"modules/pam_unix/bigcrypt.c"},"deprecated":false,"digest":{"line_hashes":["236274917370666437465787812312716913764","191165804437170388625080527033927485485","248212176959400049713618959841331975794","74187730262540881415256141112760525222","53241490001132424225404146543772968193","169694962436386515826333909717745520461","339114646913897635961686157876483083914","200902990943821488650428420571812193360"],"threshold":0.9}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/linux-pam/linux-pam/commit/225f17470eed9f44282f435ad1ed64c94d9a2ddf","target":{"file":"modules/pam_unix/bigcrypt.c","function":"bigcrypt"},"deprecated":false,"digest":{"function_hash":"251657082591479008743931529537448873642","length":1660},"id":"CVE-2020-27780-febf053a"}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}