Lucene search

K
cve[email protected]CVE-2009-2482
HistoryJul 16, 2009 - 4:30 p.m.

CVE-2009-2482

2009-07-1616:30:00
CWE-264
web.nvd.nist.gov
23
pam_unix
openpam
netbsd
cve-2009-2482
security
vulnerability
nvd

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is already known, even when they are not in the wheel group.

Affected configurations

NVD
Node
netbsdnetbsdMatch4.0
OR
netbsdnetbsdMatch4.0beta
OR
netbsdnetbsdMatch4.0beta2
OR
netbsdnetbsdMatch4.0.1
OR
netbsdnetbsdMatch4.1
OR
netbsdnetbsdMatch5.0
OR
netbsdnetbsdMatch5.0rc3

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2009-2482