Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-0579

Опубликовано: 16 апр. 2009
Источник: debian
EPSS Низкий

Описание

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pamfixed1.0.1-10package

Примечания

  • the ability to change a password earlier than scheduled is not a security

  • vulnerability in itself (unless the user changes their password back to

  • their previous password; thus violating the security policy as defined by

  • the administrator)

EPSS

Процентиль: 19%
0.00062
Низкий

Связанные уязвимости

ubuntu
больше 16 лет назад

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

redhat
почти 17 лет назад

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

nvd
больше 16 лет назад

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

github
больше 3 лет назад

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

EPSS

Процентиль: 19%
0.00062
Низкий