cbcvebase.
CVE-2009-3232
published 2009-09-17

CVE-2009-3232: pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules…

PriorityP354critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.61%
90.6th percentile
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.

Affected

7 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianpam< pam 1.0.1-10 (bookworm)pam 1.0.1-10 (bookworm)
pampam>= 0 < 1.0.1-101.0.1-10
pampam>= 0 < 1.0.1-101.0.1-10
pampam>= 0 < 1.0.1-101.0.1-10
pampam>= 0 < 1.0.1-101.0.1-10

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.