Pedro Lineu Orso chetcpasswd 2.4.1 and earlier verifies and updates user accounts via custom code that processes /etc/shadow and does not follow the PAM configuration, which might allow remote attackers to bypass intended restrictions implemented through PAM.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:21:22

Updated: 2022-10-03T16:21:22

Reserved: 2022-10-03T00:00:00


Link: CVE-2006-6683

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2006-12-21T19:28:00.000

Modified: 2019-11-13T18:53:40.670


Link: CVE-2006-6683

JSON object: View

cve-icon Redhat Information

No data.

CWE