CVE-2009-3232
17.09.2009, 10:30
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.Enginsight
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 8.10 |
| canonical | ubuntu_linux | 9.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References