CVE-2009-3232
published 2009-09-17CVE-2009-3232: pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules…
PriorityP354critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.61%
90.6th percentile
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | pam | < pam 1.0.1-10 (bookworm) | pam 1.0.1-10 (bookworm) |
| pam | pam | >= 0 < 1.0.1-10 | 1.0.1-10 |
| pam | pam | >= 0 < 1.0.1-10 | 1.0.1-10 |
| pam | pam | >= 0 < 1.0.1-10 | 1.0.1-10 |
| pam | pam | >= 0 < 1.0.1-10 | 1.0.1-10 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PAM vulnerability
vendor_ubuntu·2009-09-08
CVE-2009-3232 PAM vulnerability
Title: PAM vulnerability
Summary: PAM vulnerability
Russell Senior discovered that the system authentication module
selection mechanism for PAM did not safely handle an empty selection.
If an administrator had specifically removed the default list of modules
or failed to chose a module when operating debconf in a very unlikely
non-default configuration, PAM would allow any authentication attempt,
which could lead to remote attackers gaining access to a system with
arbitrary privileges. This did not affect default Ubuntu installations.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2009-3232: pam - pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, d...
vendor_debian·2009·CVSS 9.3
CVE-2009-3232 [CRITICAL] CVE-2009-3232: pam - pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, d...
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.
Scope: local
bookworm: resolved (fixed in 1.0.1-10)
bullseye: resolved (fixed in 1.0.1-10)
forky: resolved (fixed in 1.0.1-10)
sid: resolved (fixed in 1.0.1-10)
trixie: resolved (fixed in 1.0.1-10)
GHSA
GHSA-6jvj-39c6-mh4m: pam-auth-update for PAM, as used in Ubuntu 8
ghsa_unreviewed·2022-05-02
CVE-2009-3232 [HIGH] CWE-287 GHSA-6jvj-39c6-mh4m: pam-auth-update for PAM, as used in Ubuntu 8
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.
OSV
CVE-2009-3232: pam-auth-update for PAM, as used in Ubuntu 8
osv·2009-09-17·CVSS 9.3
CVE-2009-3232 [CRITICAL] CVE-2009-3232: pam-auth-update for PAM, as used in Ubuntu 8
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=519927http://secunia.com/advisories/36620http://www.openwall.com/lists/oss-security/2009/09/08/7http://www.securityfocus.com/bid/36306https://launchpad.net/bugs/410171https://usn.ubuntu.com/828-1/http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=519927http://secunia.com/advisories/36620http://www.openwall.com/lists/oss-security/2009/09/08/7http://www.securityfocus.com/bid/36306https://launchpad.net/bugs/410171https://usn.ubuntu.com/828-1/
2009-09-17
Published