| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.53277 |
| Kategorie: | Debian Local Security Checks |
| Titel: | Debian Security Advisory DSA 585-1 (shadow) |
| Zusammenfassung: | Debian Security Advisory DSA 585-1 (shadow) |
| Beschreibung: | The remote host is missing an update to shadow announced via advisory DSA 585-1. A vulnerability has been discovered in the shadow suite which provides programs like chfn and chsh. It is possible for a user, who is logged in but has an expired password to alter his account information with chfn or chsh without having to change the password. The problem was originally thought to be more severe. For the stable distribution (woody) this problem has been fixed in version 20000902-12woody1. For the unstable distribution (sid) this problem has been fixed in version 4.0.3-30.3. We recommend that you upgrade your passwd package (from the shadow Solution: http://www.securityspace.com/smysecure/catid.html?in=DSA%20585-1 |
| Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2004-1001 Conectiva Linux advisory: CLA-2004:894 http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000894 Debian Security Information: DSA-585 (Google Search) http://www.debian.org/security/2004/dsa-585 http://secunia.com/advisories/13028 XForce ISS Database: shadow-pwdcheck-modify-account(17902) http://xforce.iss.net/xforce/xfdb/17902 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|