vipw in the util-linux package before 2.10 causes /etc/shadow to be world-readable in some cases, which would make it easier for local users to perform brute force password guessing.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Util-linux | Andries_brouwer | 2.10s (including) | 2.10s (including) |
Util-linux | Andries_brouwer | 2.11d (including) | 2.11d (including) |
Red Hat Linux 7.1 | RedHat | * | |
Red Hat Linux 7.1 | RedHat | * | |
Red Hat Linux 7.2 | RedHat | * |