Gentoo: GLSA-200411-09: shadow: Unauthorized modification of account information
Summary
Gentoo Linux Security Advisory GLSA 200411-09
https://security.gentoo.org/
Severity: Low
Title: shadow: Unauthorized modification of account information
Date: November 04, 2004
Bugs: #69212
ID: 200411-09
Synopsis
=======
A flaw in the chfn and chsh utilities might allow modification of
account properties by unauthorized users.
Background
=========
shadow provides a set of utilities to deal with user accounts.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 sys-apps/shadow < 4.0.5-r1 >= 4.0.5-r1
==========
Martin Schulze reported a flaw in the passwd_check() function in
"libmisc/pwdcheck.c" which is used by chfn and chsh.
Impact
=====
A local attacker m...
Resolution
References
Availability
Concerns
Background