CVE Vulnerabilities

CVE-2005-0580

Published: Feb 25, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.

Affected Software

NameVendorStart VersionEnd Version
Cmd5checkpwKrzysztof_dabrowski0.20 (including)0.20 (including)
Cmd5checkpwKrzysztof_dabrowski0.21 (including)0.21 (including)
Cmd5checkpwKrzysztof_dabrowski0.22 (including)0.22 (including)

References