CVE-2009-0579

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

Published: 2009-04-16 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2009-0579 is rated Low Risk (24.2/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2009-0579

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-17 0.04% 0.06% +0.02%
2 2023-03-07 1.03% 0.04% -0.99%
3 2023-02-13 1.03%

Full EPSS history (5 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2009-0579

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.6 2.0 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
3.9 6.4 [email protected]

Weakness enumeration for CVE-2009-0579

OS Trackers for CVE-2009-0579

vendor priority summary link
debian unimportant CVE-2009-0579 unimportant priority: Debian including 1 source packages (pam), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2009-0579
redhat low https://access.redhat.com/security/cve/CVE-2009-0579
ubuntu low CVE-2009-0579 low priority: Ubuntu including 1 source packages (pam), 8 status rows across 8 suites (dapper, hardy, intrepid, jaunty, karmic, lucid, maverick, upstream): not-affected 5, ignored 2, released 1. https://ubuntu.com/security/CVE-2009-0579

Vendor comments (NVD) for CVE-2009-0579

  • Red Hat (2009-04-16T00:00:00)

    Not vulnerable. This issue did not affect the versions of pam as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5. Only PAM versions 1.x were affected.

Affected software / configurations for CVE-2009-0579

Vendor Product Version Raw CPE
linux-pam linux-pam <= 1.0.4 cpe:2.3:a:linux-pam:linux-pam:*:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.1.0 cpe:2.3:a:linux-pam:linux-pam:0.99.1.0:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.2.0 cpe:2.3:a:linux-pam:linux-pam:0.99.2.0:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.2.1 cpe:2.3:a:linux-pam:linux-pam:0.99.2.1:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.3.0 cpe:2.3:a:linux-pam:linux-pam:0.99.3.0:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.4.0 cpe:2.3:a:linux-pam:linux-pam:0.99.4.0:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.5.0 cpe:2.3:a:linux-pam:linux-pam:0.99.5.0:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.6.0 cpe:2.3:a:linux-pam:linux-pam:0.99.6.0:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.6.1 cpe:2.3:a:linux-pam:linux-pam:0.99.6.1:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.6.2 cpe:2.3:a:linux-pam:linux-pam:0.99.6.2:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.6.3 cpe:2.3:a:linux-pam:linux-pam:0.99.6.3:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.7.0 cpe:2.3:a:linux-pam:linux-pam:0.99.7.0:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.7.1 cpe:2.3:a:linux-pam:linux-pam:0.99.7.1:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.8.0 cpe:2.3:a:linux-pam:linux-pam:0.99.8.0:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.8.1 cpe:2.3:a:linux-pam:linux-pam:0.99.8.1:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.9.0 cpe:2.3:a:linux-pam:linux-pam:0.99.9.0:*:*:*:*:*:*:*
linux-pam linux-pam 0.99.10.0 cpe:2.3:a:linux-pam:linux-pam:0.99.10.0:*:*:*:*:*:*:*
linux-pam linux-pam 1.0.0 cpe:2.3:a:linux-pam:linux-pam:1.0.0:*:*:*:*:*:*:*
linux-pam linux-pam 1.0.1 cpe:2.3:a:linux-pam:linux-pam:1.0.1:*:*:*:*:*:*:*
linux-pam linux-pam 1.0.2 cpe:2.3:a:linux-pam:linux-pam:1.0.2:*:*:*:*:*:*:*
linux-pam linux-pam 1.0.3 cpe:2.3:a:linux-pam:linux-pam:1.0.3:*:*:*:*:*:*:*

References for CVE-2009-0579

cvelogic Threat Intelligence