[go: up one dir, main page]

|
|
Log in / Subscribe / Register

poppassd_pam: unauthorized password changing

Package(s):poppassd_pam CVE #(s):CAN-2005-0002
Created:January 11, 2005 Updated:January 12, 2005
Description: Gentoo Linux developer Marcus Hanwell discovered that poppassd_pam did not check that the old password was valid before changing passwords. Subsequent investigation revealed that poppassd_pam did not call pam_authenticate before calling pam_chauthtok.
Alerts:
Gentoo 200501-22 poppassd_ceti 2005-01-11

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds