cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cmd5checkpw | Krzysztof_dabrowski | 0.20 (including) | 0.20 (including) |
Cmd5checkpw | Krzysztof_dabrowski | 0.21 (including) | 0.21 (including) |
Cmd5checkpw | Krzysztof_dabrowski | 0.22 (including) | 0.22 (including) |