CVE-2004-1001: Medium severity Debian shadow vulnerability
Unknown vulnerability in the passwdcheck function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pamchauthtok function call is not properly handled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1001?
CVE-2004-1001 is classified as a moderate severity vulnerability due to its potential to facilitate unauthorized local actions.
How do I fix CVE-2004-1001?
To fix CVE-2004-1001, upgrade to Shadow version 4.0.5 or later, where the issue is resolved.
Who is affected by CVE-2004-1001?
CVE-2004-1001 affects local users of Shadow 4.0.4.1 and potentially older versions before 4.0.5.
What impact does CVE-2004-1001 have on systems?
CVE-2004-1001 can allow local users to perform unauthorized activities due to improper error handling in the passwd_check function.
What software is specifically vulnerable to CVE-2004-1001?
The specific vulnerable software mentioned in CVE-2004-1001 is Shadow version 4.0.4.1 and possibly earlier versions.