Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200501-22
https://security.gentoo.org/
Severity: High
Title: poppassd_pam: Unauthorized password changing
Date: January 11, 2005
Bugs: #75820
ID: 200501-22
Synopsis
=======
poppassd_pam allows anyone to change any user's password without
authenticating the user first.
Background
=========
poppassd_pam is a PAM-enabled server for changing system passwords that
can be used to change POP server passwords.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
net-mail/poppassd_ceti <= 1.0 >= 1.8.4
net-mail/poppassd_pam <= 1.0 Vulnerable!
-------------------------------------------------------------------
==========
Gentoo Linux developer Marcus Hanwell discovered that poppassd_pam did
not check that the old password was valid before c...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.