CVE-2004-1001
published 2005-03-01CVE-2004-1001: Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized…
PriorityP47medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.35%
27.0th percentile
Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | shadow | < shadow 1:4.0.3-35 (bookworm) | shadow 1:4.0.3-35 (bookworm) |
| debian | shadow | — | — |
| shadow_project | shadow | >= 0 < 1:4.0.3-35 | 1:4.0.3-35 |
| shadow_project | shadow | >= 0 < 1:4.0.3-35 | 1:4.0.3-35 |
| shadow_project | shadow | >= 0 < 1:4.0.3-35 | 1:4.0.3-35 |
| shadow_project | shadow | >= 0 < 1:4.0.3-35 | 1:4.0.3-35 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
passwd vulnerability
vendor_ubuntu·2004-11-05
CVE-2004-1001 passwd vulnerability
Title: passwd vulnerability
Summary: passwd vulnerability
Martin Schulze and Steve Grubb discovered a flaw in the authentication
input validation of the "chfn" and "chsh" programs. This allowed
logged in users with an expired password to change their real name and
their login shell without having to change their password.
This flaw cannot lead to privilege escalation and does not allow to
modify account properties of other users, so the impact is relatively
low.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2004-1001: shadow - Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possib...
vendor_debian·2004·CVSS 4.6
CVE-2004-1001 [MEDIUM] CVE-2004-1001: shadow - Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possib...
Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.
Scope: local
bookworm: resolved (fixed in 1:4.0.3-35)
bullseye: resolved (fixed in 1:4.0.3-35)
forky: resolved (fixed in 1:4.0.3-35)
sid: resolved (fixed in 1:4.0.3-35)
trixie: resolved (fixed in 1:4.0.3-35)
GHSA
GHSA-5j45-g3wc-p66h: Unknown vulnerability in the passwd_check function in Shadow 4
ghsa_unreviewed·2022-04-29
CVE-2004-1001 [MEDIUM] GHSA-5j45-g3wc-p66h: Unknown vulnerability in the passwd_check function in Shadow 4
Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.
OSV
CVE-2004-1001: Unknown vulnerability in the passwd_check function in Shadow 4
osv·2005-03-01·CVSS 4.6
CVE-2004-1001 [MEDIUM] CVE-2004-1001: Unknown vulnerability in the passwd_check function in Shadow 4
Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.
No detection rules found.
No writeups or analysis indexed.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000894http://secunia.com/advisories/13028http://www.debian.org/security/2004/dsa-585https://exchange.xforce.ibmcloud.com/vulnerabilities/17902http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000894http://secunia.com/advisories/13028http://www.debian.org/security/2004/dsa-585https://exchange.xforce.ibmcloud.com/vulnerabilities/17902
2005-03-01
Published