Loading...
Loading...
The local_handler_callback function in server/responder/pam/pam_LOCAL_domain.c in sssd 0.4.1 does not properly handle blank-password accounts in the SSSD BE database, which allows context-dependent attackers to obtain access by sending the account's username, in conjunction with an arbitrary password, over an ssh connection.
July 30, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-2410
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.