4.6
CVSSv2

CVE-2004-1001

Published: 01/03/2005 Updated: 11/08/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions prior to 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.

Vulnerable Product Search on Vulmon Subscribe to Product

debian shadow 4.0.4.1

Vendor Advisories

Martin Schulze and Steve Grubb discovered a flaw in the authentication input validation of the “chfn” and “chsh” programs This allowed logged in users with an expired password to change their real name and their login shell without having to change their password ...