Security Advisory

CVE-2009-3232

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-09-17 10:00:00
Last updated 2024-08-07 06:22:23
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.