Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-0579

Опубликовано: 16 апр. 2009
Источник: debian

Описание

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pamfixed1.0.1-10package

Примечания

  • the ability to change a password earlier than scheduled is not a security

  • vulnerability in itself (unless the user changes their password back to

  • their previous password; thus violating the security policy as defined by

  • the administrator)

Связанные уязвимости

ubuntu
почти 17 лет назад

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

redhat
около 17 лет назад

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

nvd
почти 17 лет назад

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

github
почти 4 года назад

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.