VulnerabilityModified
CVE-2009-2482
The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is already known, even when they are not in the wheel group.
MEDIUM 6.9EPSS 0.31%
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is already known, even when they are not in the wheel group.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.31% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- netbsd/netbsd
- Source
- cve@mitre.org
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-004.txt.asc
- http://osvdb.org/55284
- http://secunia.com/advisories/35553Vendor Advisory
- http://www.securityfocus.com/bid/35465
- http://www.securitytracker.com/id?1022432
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51312
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-004.txt.asc
- http://osvdb.org/55284
- http://secunia.com/advisories/35553Vendor Advisory
- http://www.securityfocus.com/bid/35465
- http://www.securitytracker.com/id?1022432
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51312
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.