CVE-2009-1384
Published May 28, 2009
Last updated 6 years ago
Overview
- Description
- pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-287
Vendor comments
- Red HatThis issue did not affect the versions of the pam_krb5 packages, as shipped with Red Hat Enterprise Linux 3 and 4. The issue was addressed in the pam_krb5 packages as shipped with Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2010-0258.html
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AA9B3CC0-DF1C-4A86-B2A3-A9D428A5A6E6" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:5:*:client:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7361D8F0-FE84-41D0-9C62-F180339DD40A" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:5:*:client_workstation:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5454336D-724E-4027-A642-1EFCB79C1ADC" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:5:*:server:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5833A489-D6DE-4D51-9E74-189CBC2E28CA" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:eyrie:pam-krb5:2.2.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D57B9A37-0003-4E3D-B0FE-9BEA46D26FF1" }, { "criteria": "cpe:2.3:a:eyrie:pam-krb5:2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81821DD4-343A-4CDE-A7A6-CA606662971C" }, { "criteria": "cpe:2.3:a:eyrie:pam-krb5:2.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0F34ECE-67B4-4B0A-BB57-A0A8F666669C" } ], "operator": "OR" } ], "operator": "AND" } ]