PT-2005-1140 · Poppassd · Poppassd Pam
Marcus Hanwell
·
Published
2005-01-19
·
Updated
2008-09-10
·
CVE-2005-0002
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
poppassd pam versions 1.0 and earlier
Description
The issue allows remote attackers to change passwords for arbitrary users because it does not verify that the user entered the old password correctly when changing a user password.
Recommendations
For versions 1.0 and earlier, update to a version that includes the fix for this issue to ensure proper verification of old passwords during the password change process.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Poppassd Pam