CVE-2009-0579
published 2009-04-16CVE-2009-0579: Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security…
PriorityP414medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.35%
27.3th percentile
Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.0.1-10 (bookworm) | pam 1.0.1-10 (bookworm) |
| linux-pam | linux-pam | <= 1.0.4 | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| pam | pam | >= 0 < 1.0.1-10 | 1.0.1-10 |
| pam | pam | >= 0 < 1.0.1-10 | 1.0.1-10 |
| pam | pam | >= 0 < 1.0.1-10 | 1.0.1-10 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pam: MINDAYS not respected by pam for password changing
vendor_redhat·2009-02-07·CVSS 4.6
CVE-2009-0579 [MEDIUM] pam: MINDAYS not respected by pam for password changing
pam: MINDAYS not respected by pam for password changing
Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.
Statement: Not vulnerable. This issue did not affect the versions of pam as shipped with Red Hat Enterprise Linux 3, 4, 5, or 6.
Debian
CVE-2009-0579: pam - Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as sp...
vendor_debian·2009·CVSS 4.6
CVE-2009-0579 [MEDIUM] CVE-2009-0579: pam - Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as sp...
Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.
Scope: local
bookworm: resolved (fixed in 1.0.1-10)
bullseye: resolved (fixed in 1.0.1-10)
forky: resolved (fixed in 1.0.1-10)
sid: resolved (fixed in 1.0.1-10)
trixie: resolved (fixed in 1.0.1-10)
GHSA
GHSA-hm9c-qrxw-gvc3: Linux-PAM before 1
ghsa_unreviewed·2022-05-02
CVE-2009-0579 [MEDIUM] GHSA-hm9c-qrxw-gvc3: Linux-PAM before 1
Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.
OSV
CVE-2009-0579: Linux-PAM before 1
osv·2009-04-16·CVSS 4.6
CVE-2009-0579 [MEDIUM] CVE-2009-0579: Linux-PAM before 1
Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0579 pam: MINDAYS not respected by pam for password changing [Fdevel]
bugzilla·2009-02-24·CVSS 4.6
CVE-2009-0579 [MEDIUM] CVE-2009-0579 pam: MINDAYS not respected by pam for password changing [Fdevel]
CVE-2009-0579 pam: MINDAYS not respected by pam for password changing [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2009-0579 pam: MINDAYS not respected by pam for password changing [F10]
bugzilla·2009-02-24·CVSS 4.6
CVE-2009-0579 [MEDIUM] CVE-2009-0579 pam: MINDAYS not respected by pam for password changing [F10]
CVE-2009-0579 pam: MINDAYS not respected by pam for password changing [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%2010&bugs=487217,
---
pam-1.0.4-2.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/pam-1.0.4-2.fc9
---
pam-1.0.4-2.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/pam-1.0.4-2.fc10
---
pam-1.0.4-2.fc10 has been pushed to the Fedora 10 testing repository. If problems still persist, please make note of it in this bug report.
I
Bugzilla
CVE-2009-0579 pam: MINDAYS not respected by pam for password changing [F9]
bugzilla·2009-02-24·CVSS 4.6
CVE-2009-0579 [MEDIUM] CVE-2009-0579 pam: MINDAYS not respected by pam for password changing [F9]
CVE-2009-0579 pam: MINDAYS not respected by pam for password changing [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=487218,
---
pam-1.0.4-3.fc9 has been pushed to the Fedora 9 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can install it with
su -c 'yum --enablerepo=updates-testing-newkey update pam'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F9/FEDORA-2009-3061
---
pam-1.0.4-4.fc9 has been su
Bugzilla
CVE-2009-0579 pam: MINDAYS not respected by pam for password changing
bugzilla·2009-02-24·CVSS 4.6
CVE-2009-0579 [MEDIUM] CVE-2009-0579 pam: MINDAYS not respected by pam for password changing
CVE-2009-0579 pam: MINDAYS not respected by pam for password changing
An issue dealing with password changes, with respect to the MINDAYS field in /etc/shadow was reported on the Debian BTS (http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514437) that affects all versions of PAM 1.x. Because of this, if an administrative user sets the password minimum days via chage or passwd, /etc/shadow is updated correctly, but PAM allows the user to change their password with no regard for the MINDAYS setting, effectively allowing them to re-use old passwords immediately and disregard any established password policies that should be enforced.
This is due to the fact that no minimum age password checks are done by PAM in 1.x; in the old versions it was done in _unix_verify_shadow() by checking the va
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514437http://secunia.com/advisories/34728http://secunia.com/advisories/34733https://bugzilla.redhat.com/show_bug.cgi?id=487216https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00398.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00420.htmlhttps://www.redhat.com/archives/pam-list/2009-March/msg00006.htmlhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514437http://secunia.com/advisories/34728http://secunia.com/advisories/34733https://bugzilla.redhat.com/show_bug.cgi?id=487216https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00398.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00420.htmlhttps://www.redhat.com/archives/pam-list/2009-March/msg00006.html
2009-04-16
Published