                  pam_krb5 user enumeration vulnerability
                               5 March 2010


Product:           pam_krb5
Publisher:         Mandriva
Operating System:  Mandriva Linux
                   UNIX variants (UNIX, Linux, OSX)
Impact/Access:     Reduced Security -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2009-1384  

Original Bulletin: 

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Mandriva. It is recommended that administrators
         running pam_krb5 check for an updated version of the software for
         their operating system.

 Mandriva Linux Security Advisory                         MDVSA-2010:054

 Package : pam_krb5
 Date    : March 4, 2010
 Affected: 2009.0, 2009.1, Enterprise Server 5.0

 Problem Description:

 Pam_krb5 2.2.14 through 2.3.4 generates different password prompts
 depending on whether the user account exists, which allows remote
 attackers to enumerate valid usernames (CVE-2009-1384).
 This update provides the version 2.3.5 of pam_krb5, which is not
 vulnerable to this issue.



