Gentoo: GLSA-200502-30: cmd5checkpw: Local password leak vulnerability
Summary
Gentoo Linux Security Advisory GLSA 200502-30
https://security.gentoo.org/
Severity: Low
Title: cmd5checkpw: Local password leak vulnerability
Date: February 25, 2005
Bugs: #78256
ID: 200502-30
Synopsis
=======
cmd5checkpw contains a flaw allowing local users to access other userscmd5checkpw passwords.
Background
=========
cmd5checkpw is a checkpassword compatible authentication program that
uses CRAM-MD5 authentication mode.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-mail/cmd5checkpw <= 0.22-r1 >= 0.22-r2
==========
Florian Westphal discovered that cmd5checkpw is installed setuid
cmd5checkpw but does not drop privileges before calling execvp(), s...
Resolution
References
Availability
Concerns
Background