Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-3232

Опубликовано: 17 сент. 2009
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00539
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 16 лет назад

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.

debian
больше 16 лет назад

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GN ...

github
больше 3 лет назад

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.

EPSS

Процентиль: 67%
0.00539
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-287