|
|
Log in / Subscribe / Register

pam_krb5: information disclosure

Package(s):pam_krb5 CVE #(s):CVE-2009-1384
Created:June 29, 2009 Updated:March 31, 2010
Description:

From the Red Hat bugzilla entry:

A security flaw was found in PAM pam_krb5 module, providing user authentication based on Kerberos principals. A remote attacker could use this flaw to recognize, if some username/login belongs to set of user accounts, existing on the system, and subsequently perform dictionary based password guess attack.

Alerts:
Red Hat RHSA-2010:0258-04 pam_krb5 2010-03-30
Mandriva MDVSA-2010:054 pam_krb5 2010-03-04
Fedora FEDORA-2009-5983 pam_krb5 2009-06-15
Fedora FEDORA-2009-6255 pam_krb5 2009-06-15
Fedora FEDORA-2009-6279 pam_krb5 2009-06-15

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds