Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Gentoo: GLSA-200502-30 Low: cmd5checkpw Local Password Exposure

gentoo
Calendar Grey February 25, 2005
Scroller Gentoo
Gentoo security announcement GLSA 200602-45: cmd5checkpw local privilege vulnerability reveals user credentials, severity medium.
cmd5checkpw contains a flaw allowing local users to access other users cmd5checkpw passwords.

Summary

Gentoo Linux Security Advisory GLSA 200502-30 https://security.gentoo.org/ Severity: Low Title: cmd5checkpw: Local password leak vulnerability Date: February 25, 2005 Bugs: #78256 ID: 200502-30

Synopsis ======= cmd5checkpw contains a flaw allowing local users to access other userscmd5checkpw passwords.
Background ========= cmd5checkpw is a checkpassword compatible authentication program that uses CRAM-MD5 authentication mode.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-mail/cmd5checkpw <= 0.22-r1 >= 0.22-r2
========== Florian Westphal discovered that cmd5checkpw is installed setuid cmd5checkpw but does not drop privileges before calling execvp(), s...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
low
Lowest
Low
Medium
High
Critical

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround