Oval Definition:oval:org.mitre.oval:def:13240
Revision Date:2014-06-30Version:20
Title:USN-828-1 -- pam vulnerability
Description:Russell Senior discovered that the system authentication module selection mechanism for PAM did not safely handle an empty selection. If an administrator had specifically removed the default list of modules or failed to chose a module when operating debconf in a very unlikely non-default configuration, PAM would allow any authentication attempt, which could lead to remote attackers gaining access to a system with arbitrary privileges. This did not affect default Ubuntu installations.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-3232
USN-828-1
USN-828-1
Platform(s):Ubuntu 8.10
Ubuntu 9.04
Product(s):pam
Definition Synopsis
  • Release section
  • Ubuntu 8.10 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • libpam-runtime DPKG is earlier than 1.0.1-4ubuntu5.6
  • OR libpam-doc DPKG is earlier than 1.0.1-4ubuntu5.6
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • libpam0g-dev DPKG is earlier than 1.0.1-4ubuntu5.6
  • OR libpam-modules DPKG is earlier than 1.0.1-4ubuntu5.6
  • OR libpam0g DPKG is earlier than 1.0.1-4ubuntu5.6
  • OR libpam-cracklib DPKG is earlier than 1.0.1-4ubuntu5.6
  • OR Release section
  • Ubuntu 9.04 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • libpam-runtime DPKG is earlier than 1.0.1-9ubuntu1.1
  • OR libpam-doc DPKG is earlier than 1.0.1-9ubuntu1.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • libpam0g-dev DPKG is earlier than 1.0.1-9ubuntu1.1
  • OR libpam-modules DPKG is earlier than 1.0.1-9ubuntu1.1
  • OR libpam0g DPKG is earlier than 1.0.1-9ubuntu1.1
  • OR libpam-cracklib DPKG is earlier than 1.0.1-9ubuntu1.1
  • BACK