Jump to content

Advisories MDVSA-2010:054: pam_krb5


paul
 Share

Recommended Posts

Pam_krb5 2.2.14 through 2.3.4 generates different password prompts

depending on whether the user account exists, which allows remote

attackers to enumerate valid usernames (CVE-2009-1384).

 

This update provides the version 2.3.5 of pam_krb5, which is not

vulnerable to this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...