Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200502-30
https://security.gentoo.org/
Severity: Low
Title: cmd5checkpw: Local password leak vulnerability
Date: February 25, 2005
Bugs: #78256
ID: 200502-30
Synopsis
=======
cmd5checkpw contains a flaw allowing local users to access other userscmd5checkpw passwords.
Background
=========
cmd5checkpw is a checkpassword compatible authentication program that
uses CRAM-MD5 authentication mode.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-mail/cmd5checkpw <= 0.22-r1 >= 0.22-r2
==========
Florian Westphal discovered that cmd5checkpw is installed setuid
cmd5checkpw but does not drop privileges before calling execvp(), s...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.