pam_krb5: information disclosure
| Package(s): | pam_krb5 | CVE #(s): | CVE-2009-1384 | ||||||||||||||||||||
| Created: | June 29, 2009 | Updated: | March 31, 2010 | ||||||||||||||||||||
| Description: | From the Red Hat bugzilla entry: A security flaw was found in PAM pam_krb5 module, providing user authentication based on Kerberos principals. A remote attacker could use this flaw to recognize, if some username/login belongs to set of user accounts, existing on the system, and subsequently perform dictionary based password guess attack. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
