9.3
CVSSv2

CVE-2009-3232

Published: 17/09/2009 Updated: 13/02/2024
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote malicious users to bypass authentication.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 9.04

canonical ubuntu linux 8.10

Vendor Advisories

Russell Senior discovered that the system authentication module selection mechanism for PAM did not safely handle an empty selection If an administrator had specifically removed the default list of modules or failed to chose a module when operating debconf in a very unlikely non-default configuration, PAM would allow any authentication attempt, wh ...