First published: Thu Nov 04 2004(Updated: )
Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Shadow-utils | =4.0.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1001 is classified as a moderate severity vulnerability due to its potential to facilitate unauthorized local actions.
To fix CVE-2004-1001, upgrade to Shadow version 4.0.5 or later, where the issue is resolved.
CVE-2004-1001 affects local users of Shadow 4.0.4.1 and potentially older versions before 4.0.5.
CVE-2004-1001 can allow local users to perform unauthorized activities due to improper error handling in the passwd_check function.
The specific vulnerable software mentioned in CVE-2004-1001 is Shadow version 4.0.4.1 and possibly earlier versions.