Local Authentication Bypass in Shadow by Sun Microsystems
CVE-2004-1001

Currently unrated

Key Information:

Vendor
Debian
Status
Vendor
CVE Published:
1 March 2005

Summary

An unaddressed vulnerability in the passwd_check function present in Shadow could allow local users to exploit improper error handling from the pam_chauthtok function. This flaw potentially enables unauthorized activities, compromising system security if the flaw is not remediated.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.