CVE Vulnerabilities

CVE-2009-1273

Published: Apr 08, 2009 | Modified: May 13, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.

Affected Software

Name Vendor Start Version End Version
Pam_ssh Andrew_j.korty 1.92 (including) 1.92 (including)

References