7.5
CVSSv2

CVE-2009-2410

Published: 30/07/2009 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The local_handler_callback function in server/responder/pam/pam_LOCAL_domain.c in sssd 0.4.1 does not properly handle blank-password accounts in the SSSD BE database, which allows context-dependent malicious users to obtain access by sending the account's username, in conjunction with an arbitrary password, over an ssh connection.

Vulnerable Product Search on Vulmon Subscribe to Product

fedorahosted sssd 0.4.1