{"id":"DEBIAN-CVE-2009-1273","details":"pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.","modified":"2026-09-22T16:47:27.521368852Z","published":"2009-04-08T18:30:00.233Z","upstream":["CVE-2009-1273"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2009-1273"}],"affected":[{"package":{"name":"libpam-ssh","ecosystem":"Debian:13","purl":"pkg:deb/debian/libpam-ssh?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.92-7"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-1273.json"}},{"package":{"name":"libpam-ssh","ecosystem":"Debian:14","purl":"pkg:deb/debian/libpam-ssh?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.92-7"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-1273.json"}}],"schema_version":"1.9.0"}