Unknown vulnerability in the passwdcheck function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pamchauthtok function call is not properly handled.
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees