CVE Vulnerabilities

CVE-2009-2482

Published: Jul 16, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is already known, even when they are not in the wheel group.

Affected Software

NameVendorStart VersionEnd Version
NetbsdNetbsd4.0 (including)4.0 (including)
NetbsdNetbsd4.0-beta (including)4.0-beta (including)
NetbsdNetbsd4.0-beta2 (including)4.0-beta2 (including)
NetbsdNetbsd4.0.1 (including)4.0.1 (including)
NetbsdNetbsd4.1 (including)4.1 (including)
NetbsdNetbsd5.0 (including)5.0 (including)
NetbsdNetbsd5.0-rc3 (including)5.0-rc3 (including)

References