CVE Vulnerabilities

CVE-2005-0580

Published: Feb 25, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.

Affected Software

Name Vendor Start Version End Version
Cmd5checkpw Krzysztof_dabrowski 0.20 (including) 0.20 (including)
Cmd5checkpw Krzysztof_dabrowski 0.21 (including) 0.21 (including)
Cmd5checkpw Krzysztof_dabrowski 0.22 (including) 0.22 (including)

References