A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated users to bypass intended access restrictions and send requests to OpenPegasus WBEM services.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9556
https://exchange.xforce.ibmcloud.com/vulnerabilities/46829
https://bugzilla.redhat.com/show_bug.cgi?id=459217
https://admin.fedoraproject.org/updates/tog-pegasus-2.7.1-3.fc10
https://admin.fedoraproject.org/updates/tog-pegasus-2.7.0-7.fc9
http://www.securitytracker.com/id?1021283
http://www.securityfocus.com/bid/32460
http://www.redhat.com/support/errata/RHSA-2008-1001.html