Podatność CVE-2009-3232


Publikacja: 2009-09-17   Modyfikacja: 2012-02-13

Opis:
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.

Typ:

CWE-287

(Improper Authentication)

Producent: Ubuntu
Produkt: Ubuntu linux 
Wersje: 9.04; 8.10;
Producent: Debian
Produkt: Debian linux 

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

Ogólna skala CVSS
Znaczenie
Łatwość wykorzystania
9.3/10
10/10
8.6/10
Wymagany dostęp
Złożoność ataku
Autoryzacja
Zdalny
Średnia
Nie wymagana
Wpływ na poufność
Wpływ na integralność
Wpływ na dostępność
Pełny
Pełny
Pełny

 Referencje:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=519927
http://www.openwall.com/lists/oss-security/2009/09/08/7
http://www.securityfocus.com/bid/36306
https://launchpad.net/bugs/410171
https://usn.ubuntu.com/828-1/

Podobne CVE
CVE-2015-7542
An issue exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
CVE-2014-3591
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluct...
CVE-2013-7325
An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
CVE-2012-6639
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.
CVE-2012-5644
libuser has information disclosure when moving user's home directory
CVE-2011-3632
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
CVE-2011-3630
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user...
CVE-2011-4350
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.

Copyright 2019, cxsecurity.com

 

Back to Top