Back to search
CVE-2009-1384
Published: May 28, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
35230
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:9652
vdb-entry
signature
x_refsource_OVAL
https://bugzilla.redhat.com/show_bug.cgi?id=502602
x_refsource_CONFIRM
43314
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20090527 CVE assignment notification (pam_krb5 CVE-2009-1384)
mailing-list
x_refsource_MLIST
oval:org.mitre.oval:def:7081
vdb-entry
signature
x_refsource_OVAL
MDVSA-2010:054
vendor-advisory
x_refsource_MANDRIVA
54791
vdb-entry
x_refsource_OSVDB
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
x_refsource_CONFIRM
20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
mailing-list
x_refsource_BUGTRAQ
ADV-2009-1448
vdb-entry
x_refsource_VUPEN
35112
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now