PT-2004-2006 · Shadow · Shadow

Published

2004-11-04

·

Updated

2020-08-11

·

CVE-2004-1001

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Shadow versions prior to 4.0.5
Description: The issue is related to an error handling problem in the passwd check function, potentially allowing local users to perform unauthorized actions. This occurs when an error from a pam chauthtok function call is not properly handled.
Recommendations: For versions prior to 4.0.5, update to version 4.0.5 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1001
DSA-585-1

Affected Products

Shadow