CVE-2009-1384
Summary
| CVE | CVE-2009-1384 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-05-28 20:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Eyrie | Pam-krb5 | 2.2.14 | All | All | All |
| Application | Eyrie | Pam-krb5 | 2.3 | All | All | All |
| Application | Eyrie | Pam-krb5 | 2.3.4 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 5 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 5 | All | client | All |
| Operating System | Redhat | Enterprise Linux | 5 | All | client_workstation | All |
| Operating System | Redhat | Enterprise Linux | 5 | All | server | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| VMSA-2011-0003 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| 502602 – (CVE-2009-1384) CVE-2009-1384 pam_krb5: Password prompt varies for existent and non-existent users | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| osvdb.org/54791 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| pam_krb5 Existing/Non-Existing Username Enumeration Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| oss-security - CVE assignment notification (pam_krb5 CVE-2009-1384) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| pam_krb5 Password Prompt User Enumeration Security Issue - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support / Security / Advisories / / MDVSA-2010:054 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| VMware ESX Server pam_krb5 Security Issues - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-03-31 | Tomas Hoger | This issue did not affect the versions of the pam_krb5 packages, as shipped with Red Hat Enterprise Linux 3 and 4. The issue was addressed in the pam_krb5 packages as shipped with Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2010-0258.html |
There are currently no legacy QID mappings associated with this CVE.