CVE-2009-3232Improper Authentication in PAM

Severity
9.3CRITICALNVD
EPSS
0.5%
top 32.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 17
Latest updateMay 2

Description

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

debiandebian/pam< pam 1.0.1-10 (bookworm)
Debianpam/pam< 1.0.1-10+3

Also affects: Ubuntu Linux 8.10, 9.04

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6jvj-39c6-mh4m: pam-auth-update for PAM, as used in Ubuntu 82022-05-02
OSV
CVE-2009-3232: pam-auth-update for PAM, as used in Ubuntu 82009-09-17

📋Vendor Advisories

2
Ubuntu
PAM vulnerability2009-09-08
Debian
CVE-2009-3232: pam - pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, d...2009

📐Framework References

1
CWE
Improper Authentication
CVE-2009-3232 — Improper Authentication in Debian PAM | cvebase