Pedro Lineu Orso chetcpasswd 2.4.1 and earlier verifies and updates user accounts via custom code that processes /etc/shadow and does not follow the PAM configuration, which might allow remote attackers to bypass intended restrictions implemented through PAM.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Chetcpasswd | Pedro_lineu_orso | * | 2.4.1 (including) |
Chetcpasswd | Pedro_lineu_orso | 1.12 (including) | 1.12 (including) |
Chetcpasswd | Pedro_lineu_orso | 2.1 (including) | 2.1 (including) |
Chetcpasswd | Pedro_lineu_orso | 2.2.1 (including) | 2.2.1 (including) |
Chetcpasswd | Pedro_lineu_orso | 2.3.1 (including) | 2.3.1 (including) |
Chetcpasswd | Pedro_lineu_orso | 2.3.3 (including) | 2.3.3 (including) |