Description
Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.
CVSS vector
AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4 Affected Packages3 packages
🔴Vulnerability Details
2GHSAGHSA-hm9c-qrxw-gvc3: Linux-PAM before 1↗2022-05-02 ▶ OSVCVE-2009-0579: Linux-PAM before 1↗2009-04-16 ▶ 📋Vendor Advisories
2Red Hatpam: MINDAYS not respected by pam for password changing↗2009-02-07 ▶ DebianCVE-2009-0579: pam - Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as sp...↗2009 ▶ 💬Community
4BugzillaCVE-2009-0579 pam: MINDAYS not respected by pam for password changing [Fdevel]↗2009-02-24 ▶ BugzillaCVE-2009-0579 pam: MINDAYS not respected by pam for password changing [F10]↗2009-02-24 ▶ BugzillaCVE-2009-0579 pam: MINDAYS not respected by pam for password changing [F9]↗2009-02-24 ▶ BugzillaCVE-2009-0579 pam: MINDAYS not respected by pam for password changing↗2009-02-24 ▶