Eyrie develops authentication and access-control components for Unix and Linux systems, specifically PAM modules for Kerberos integration and a remote command execution tool. The observed vulnerability exposure centers on improper authentication handling and memory-safety issues in these infrastructure components, which operate in privileged contexts where flaws can directly affect system access control. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eyrie over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0360MEDIUM Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges | Feb 13, 2009 | 6.2 | 28 | NO | YES |
CVE-2018-0493HIGH remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, | Apr 3, 2018 | 7.2 | 23 | NO | NO |
CVE-2009-1384MEDIUM pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote | May 28, 2009 | 5.0 | 18 | NO | NO |
CVE-2009-0361MEDIUM Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows | Feb 13, 2009 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eyrie.
Media articles that mention a CVE ID that affects a product developed by Eyrie — matched by CVE ID, not by vendor name.