Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-0579
HistoryApr 16, 2009 - 12:00 a.m.

CVE-2009-0579

2009-04-1600:00:00
ubuntu.com
ubuntu.com
10

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS)
as specified in /etc/shadow, which allows local users to bypass intended
security policy and change their passwords sooner than specified.

Bugs

Notes

Author Note
mdeslaur pam below 1.0 have a check already as per debian bug: in _unix_verify_shadow, called from pam_sm_chauthtok: if ((curdays < (spwdent->sp_lstchg + spwdent->sp_min)) && (spwdent->sp_min != -1)) retval = PAM_AUTHTOK_ERR;

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%

Related for UB:CVE-2009-0579