A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2023-12-27T15:43:22.929Z

Updated: 2024-05-03T15:32:38.166Z

Reserved: 2023-08-30T17:16:27.137Z


Link: CVE-2023-4641

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-12-27T16:15:13.363

Modified: 2024-05-03T16:15:11.090


Link: CVE-2023-4641

JSON object: View

cve-icon Redhat Information

No data.