CVE Vulnerabilities

CVE-2009-0579

Published: Apr 16, 2009 | Modified: Jan 03, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

Affected Software

Name Vendor Start Version End Version
Linux-pam Linux-pam 0.99.1.0 0.99.1.0
Linux-pam Linux-pam 0.99.2.0 0.99.2.0
Linux-pam Linux-pam 0.99.2.1 0.99.2.1
Linux-pam Linux-pam 0.99.3.0 0.99.3.0
Linux-pam Linux-pam 0.99.4.0 0.99.4.0
Linux-pam Linux-pam 0.99.5.0 0.99.5.0
Linux-pam Linux-pam 0.99.6.0 0.99.6.0
Linux-pam Linux-pam 0.99.6.1 0.99.6.1
Linux-pam Linux-pam 0.99.6.2 0.99.6.2
Linux-pam Linux-pam 0.99.6.3 0.99.6.3
Linux-pam Linux-pam 0.99.7.0 0.99.7.0
Linux-pam Linux-pam 0.99.7.1 0.99.7.1
Linux-pam Linux-pam 0.99.8.0 0.99.8.0
Linux-pam Linux-pam 0.99.8.1 0.99.8.1
Linux-pam Linux-pam 0.99.9.0 0.99.9.0
Linux-pam Linux-pam 0.99.10.0 0.99.10.0
Linux-pam Linux-pam 1.0.0 1.0.0
Linux-pam Linux-pam 1.0.1 1.0.1
Linux-pam Linux-pam 1.0.2 1.0.2
Linux-pam Linux-pam 1.0.3 1.0.3
Linux-pam Linux-pam * 1.0.4

References