The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "1.1.8-1ubuntu2.1", "binary_name": "libpam-cracklib" }, { "binary_version": "1.1.8-1ubuntu2.1", "binary_name": "libpam-cracklib-dbgsym" }, { "binary_version": "1.1.8-1ubuntu2.1", "binary_name": "libpam-doc" }, { "binary_version": "1.1.8-1ubuntu2.1", "binary_name": "libpam-modules" }, { "binary_version": "1.1.8-1ubuntu2.1", "binary_name": "libpam-modules-bin" }, { "binary_version": "1.1.8-1ubuntu2.1", "binary_name": "libpam-modules-bin-dbgsym" }, { "binary_version": "1.1.8-1ubuntu2.1", "binary_name": "libpam-modules-dbgsym" }, { "binary_version": "1.1.8-1ubuntu2.1", "binary_name": "libpam-runtime" }, { "binary_version": "1.1.8-1ubuntu2.1", "binary_name": "libpam0g" }, { "binary_version": "1.1.8-1ubuntu2.1", "binary_name": "libpam0g-dbgsym" }, { "binary_version": "1.1.8-1ubuntu2.1", "binary_name": "libpam0g-dev" } ] }