pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://bugs.gentoo.org/show_bug.cgi?id=263579 | |
http://secunia.com/advisories/34986 | third party advisory |
http://secunia.com/advisories/34536 | third party advisory vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00116.html | vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00145.html | vendor advisory |