pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2009-09-17T10:00:00

Updated: 2024-08-07T06:22:23.335Z

Reserved: 2009-09-16T00:00:00

Link: CVE-2009-3232

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2009-09-17T10:30:01.250

Modified: 2024-02-13T17:42:02.047

Link: CVE-2009-3232

cve-icon Redhat

No data.