CVE Vulnerabilities

CVE-2009-2482

Published: Jul 16, 2009 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is already known, even when they are not in the wheel group.

Affected Software

Name Vendor Start Version End Version
Netbsd Netbsd 4.1 4.1
Netbsd Netbsd 5.0 5.0
Netbsd Netbsd 4.0 4.0
Netbsd Netbsd 4.0 4.0
Netbsd Netbsd 5.0 5.0
Netbsd Netbsd 4.0.1 4.0.1
Netbsd Netbsd 4.0 4.0

References