pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade pam_krb5 | Oct 16, 2024 | May 28, 2009 |
| Suse | — | Upgrade pam_krb5Upgrade pam_krb5-32bit | Aug 9, 2024 | Jun 28, 2013 |
| Vmsa 2010 0009 1 Service Console Update | — | Upgrade VMware ESX 4.0 to build number 256968Upgrade VMware ESX 3.5 to build number 213532 | Sep 2, 2010 | May 28, 2009 |
| Vmsa 2011 0003 | — | Upgrade VMware ESX 4.1 to build number 348481 | Feb 16, 2011 | May 28, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub