VulnerabilityModified
CVE-2009-1384
pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
MEDIUM 5.0EPSS 2.89%
Does this matter?
Lower severity and a low EPSS score (2.89%). Track it; it rarely justifies an emergency change on its own.
Description
pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.89% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- eyrie/pam-krb5
- Source
- secalert@redhat.com
References
- http://osvdb.org/54791
- http://secunia.com/advisories/35230
- http://secunia.com/advisories/43314
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:054
- http://www.openwall.com/lists/oss-security/2009/05/27/1
- http://www.securityfocus.com/archive/1/516397/100/0/threaded
- http://www.securityfocus.com/bid/35112
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html
- http://www.vupen.com/english/advisories/2009/1448
- https://bugzilla.redhat.com/show_bug.cgi?id=502602Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7081
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9652
- http://osvdb.org/54791
- http://secunia.com/advisories/35230
- http://secunia.com/advisories/43314
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:054
- http://www.openwall.com/lists/oss-security/2009/05/27/1
- http://www.securityfocus.com/archive/1/516397/100/0/threaded
- http://www.securityfocus.com/bid/35112
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html
- http://www.vupen.com/english/advisories/2009/1448
- https://bugzilla.redhat.com/show_bug.cgi?id=502602Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7081
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9652
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.