Vulnerability Name:

CVE-2009-0579 (CCN-49912)

Assigned:2009-03-04
Published:2009-03-04
Updated:2019-01-03
Summary:Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
4.0 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
1.8 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-264
Vulnerability Consequences:Other
References:Source: CCN
Type: Debian Bug report logs - #514437
chage -m / passwd -n (--mindays) have no effect (Lenny)

Source: CONFIRM
Type: UNKNOWN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514437

Source: MITRE
Type: CNA
CVE-2009-0579

Source: CCN
Type: SA34728
Linux-PAM Minimum Password Age Security Bypass Weakness

Source: SECUNIA
Type: Vendor Advisory
34728

Source: SECUNIA
Type: Vendor Advisory
34733

Source: CCN
Type: Linux-PAM Web page
Linux-PAM

Source: CCN
Type: OSVDB ID: 53688
Linux-PAM Minimum Password Age Security Bypass

Source: CONFIRM
Type: Patch
https://bugzilla.redhat.com/show_bug.cgi?id=487216

Source: XF
Type: UNKNOWN
linuxpam-pwage-weak-security(49912)

Source: FEDORA
Type: UNKNOWN
FEDORA-2009-3204

Source: FEDORA
Type: Patch, Vendor Advisory
FEDORA-2009-3231

Source: CCN
Type: pam-list Mailing List, Wed, 4 Mar 2009 11:07:57 +0100
Linux-PAM 1.0.4 released

Source: MLIST
Type: Vendor Advisory
[pam-list] 20090309 Linux-PAM 1.0.4 released

Vulnerable Configuration:Configuration 1:
  • cpe:/a:linux-pam:linux-pam:0.99.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.9.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:0.99.10.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:1.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:1.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:linux-pam:linux-pam:*:*:*:*:*:*:*:* (Version <= 1.0.4)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:42413
    P
    Recommended update for aws-efs-utils, python-ansi2html, python-py, python-pytest-html, python-pytest-metadata, python-pytest-rerunfailures, python-coverage, python-oniconfig, python-unittest-mixins (Moderate) (in QA)
    2022-05-24
    oval:org.opensuse.security:def:20090579
    V
    CVE-2009-0579
    2022-05-20
    oval:org.opensuse.security:def:42204
    P
    Security update for wpa_supplicant (Important)
    2022-03-04
    oval:org.opensuse.security:def:26185
    P
    Security update for xorg-x11-server (Important)
    2021-12-20
    oval:org.opensuse.security:def:31718
    P
    Security update for MozillaFirefox (Important)
    2021-12-12
    oval:org.opensuse.security:def:32226
    P
    Security update for webkit2gtk3 (Important)
    2021-11-23
    oval:org.opensuse.security:def:31309
    P
    Security update for postgresql10 (Important)
    2021-11-22
    oval:org.opensuse.security:def:31701
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:26149
    P
    Security update for iproute2 (Moderate)
    2021-10-18
    oval:org.opensuse.security:def:31690
    P
    Security update for webkit2gtk3 (Important)
    2021-10-06
    oval:org.opensuse.security:def:32187
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-09-23
    oval:org.opensuse.security:def:26132
    P
    Security update for MozillaFirefox (Important)
    2021-09-22
    oval:org.opensuse.security:def:26123
    P
    Security update for openssl-1_0_0 (Low)
    2021-09-09
    oval:org.opensuse.security:def:31265
    P
    Security update for xen (Important)
    2021-09-06
    oval:org.opensuse.security:def:31264
    P
    Security update for file (Important)
    2021-09-02
    oval:org.opensuse.security:def:32178
    P
    Security update for openexr (Important)
    2021-09-02
    oval:org.opensuse.security:def:26093
    P
    Security update for dbus-1 (Important)
    2021-07-21
    oval:org.opensuse.security:def:26092
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:26082
    P
    Security update for openexr (Important)
    2021-06-24
    oval:org.opensuse.security:def:26081
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:26079
    P
    Security update for gupnp (Important)
    2021-06-18
    oval:org.opensuse.security:def:36532
    P
    pam-devel-1.1.5-0.15.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42665
    P
    pam-1.1.5-0.15.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36258
    P
    pam-1.1.5-0.15.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31631
    P
    Security update for gstreamer-plugins-bad (Important)
    2021-06-07
    oval:org.opensuse.security:def:26065
    P
    Security update for polkit (Important)
    2021-06-03
    oval:org.opensuse.security:def:32091
    P
    Security update for python3 (Important)
    2021-05-17
    oval:org.opensuse.security:def:32082
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:32084
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:26026
    P
    Security update for cifs-utils (Moderate)
    2021-04-13
    oval:org.opensuse.security:def:31350
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:31736
    P
    Security update for MozillaFirefox (Important)
    2021-03-01
    oval:org.opensuse.security:def:31725
    P
    Security update for openvswitch (Important)
    2021-02-12
    oval:org.opensuse.security:def:31724
    P
    Security update for python (Important)
    2021-02-11
    oval:org.opensuse.security:def:32248
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:26157
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:32969
    P
    Security update for python36 (Important)
    2021-02-01
    oval:org.opensuse.security:def:31177
    P
    Security update for dnsmasq (Important)
    2021-01-19
    oval:org.opensuse.security:def:31276
    P
    Security update for java-1_8_0-ibm (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:32138
    P
    Security update for openssh (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:32930
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:25981
    P
    Security update for PackageKit (Low)
    2020-12-22
    oval:org.opensuse.security:def:32018
    P
    Security update for MozillaFirefox (Critical)
    2020-12-21
    oval:org.opensuse.security:def:25977
    P
    Security update for openssl-1_1 (Important)
    2020-12-10
    oval:org.opensuse.security:def:31092
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2020-12-07
    oval:org.opensuse.security:def:31091
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2020-12-07
    oval:org.opensuse.security:def:35797
    P
    pam-1.1.5-0.10.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42030
    P
    pam-1.0.4-0.5.12 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:36006
    P
    pam-1.1.5-0.10.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35623
    P
    pam-1.0.4-0.5.12 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:31558
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:25567
    P
    Security update for java-11-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:31782
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26437
    P
    Security update for enigmail (Important)
    2020-12-01
    oval:org.opensuse.security:def:32500
    P
    cyrus-imapd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25459
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:32761
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25759
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31926
    P
    Recommended update for ghostscript-library (Important)
    2020-12-01
    oval:org.opensuse.security:def:26525
    P
    avahi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33182
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25600
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31806
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26761
    P
    libpulse-browse0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25897
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:26583
    P
    libarchive2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26366
    P
    Security update for kdelibs4, kio (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25804
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31867
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25348
    P
    Security update for ucode-intel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31482
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:27256
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25807
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31810
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26507
    P
    Security update for cacti, cacti-spine (Important)
    2020-12-01
    oval:org.opensuse.security:def:25892
    P
    Security update for gstreamer-0_10-plugins-good (Important)
    2020-12-01
    oval:org.opensuse.security:def:32549
    P
    libdrm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25423
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26234
    P
    Security update for LibreOffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32292
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25819
    P
    Security update for python-tornado (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32034
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26711
    P
    gnutls on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25950
    P
    Security update for evince (Important)
    2020-12-01
    oval:org.opensuse.security:def:25632
    P
    Security update for aspell (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31874
    P
    Security update for cyrus-imapd (Important)
    2020-12-01
    oval:org.opensuse.security:def:26287
    P
    Security update for zeromq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31472
    P
    Security update for ppp (Important)
    2020-12-01
    oval:org.opensuse.security:def:26011
    P
    Security update for gwenhywfar (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26799
    P
    pam_mount on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26623
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25174
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:25773
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31979
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26969
    P
    librsvg on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31484
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:32390
    P
    Security update for tomcat6 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26857
    P
    PolicyKit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25186
    P
    Security update for ruby2.1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31401
    P
    Security update for perl-DBD-mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32040
    P
    Security update for various KMPs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25556
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26384
    P
    Security update for chromium (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32478
    P
    Security update for zsh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27530
    P
    pam-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25378
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:31545
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:32722
    P
    libopensc2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25631
    P
    Security update for tar (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31839
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26486
    P
    Security update for pdns-recursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32544
    P
    libMagickCore1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25516
    P
    Security update for file-roller (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31757
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:25840
    P
    Security update for libvirt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26539
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33221
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26285
    P
    Security update for the Linux Kernel (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25751
    P
    Security update for libssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31845
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:26796
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25347
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27221
    P
    libtevent0-x86 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26423
    P
    Security update for opencv (Important)
    2020-12-01
    oval:org.opensuse.security:def:25853
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31911
    P
    Security update for gcc43 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25359
    P
    Security update for SUSE Manager Client Tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31574
    P
    Security update for strongswan (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25808
    P
    Security update for LibreOffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31942
    P
    Security update for gnome-session (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26658
    P
    MozillaFirefox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25906
    P
    Security update for sane-backends (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32588
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25551
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:26273
    P
    Security update for libraw (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25883
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26760
    P
    libpoppler-glib4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26588
    P
    libicu-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31103
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:org.opensuse.security:def:25689
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31930
    P
    Security update for glib2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26331
    P
    Security update for Chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:31473
    P
    Security update for procmail
    2020-12-01
    oval:org.opensuse.security:def:32334
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:26813
    P
    pyxml on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25175
    P
    Security update for libssh (Important)
    2020-12-01
    oval:org.opensuse.security:def:25924
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27004
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25555
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26233
    P
    Security update for python-reportlab (Important)
    2020-12-01
    oval:org.opensuse.security:def:32439
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:27495
    P
    libtunepimp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25250
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31458
    P
    Security update for postgresql91 (Moderate)
    2020-12-01
    BACK
    linux-pam linux-pam 0.99.1.0
    linux-pam linux-pam 0.99.2.0
    linux-pam linux-pam 0.99.2.1
    linux-pam linux-pam 0.99.3.0
    linux-pam linux-pam 0.99.4.0
    linux-pam linux-pam 0.99.5.0
    linux-pam linux-pam 0.99.6.0
    linux-pam linux-pam 0.99.6.1
    linux-pam linux-pam 0.99.6.2
    linux-pam linux-pam 0.99.6.3
    linux-pam linux-pam 0.99.7.0
    linux-pam linux-pam 0.99.7.1
    linux-pam linux-pam 0.99.8.0
    linux-pam linux-pam 0.99.8.1
    linux-pam linux-pam 0.99.9.0
    linux-pam linux-pam 0.99.10.0
    linux-pam linux-pam 1.0.0
    linux-pam linux-pam 1.0.1
    linux-pam linux-pam 1.0.2
    linux-pam linux-pam 1.0.3
    linux-pam linux-pam *