It was discovered that PAM had a timing discrepancy in the pam_userdb
module when comparing plaintext passwords. An attacker could possibly use
this issue to obtain sensitive information by measuring response-timing
differences during repeated authentication attempts.