Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.
2009-04-16T15:12:57.360
2025-04-09T00:30:58.490
Deferred
CVSSv2: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | linux-pam | linux-pam | ≤ 1.0.4 | Yes |
Application | linux-pam | linux-pam | 0.99.1.0 | Yes |
Application | linux-pam | linux-pam | 0.99.2.0 | Yes |
Application | linux-pam | linux-pam | 0.99.2.1 | Yes |
Application | linux-pam | linux-pam | 0.99.3.0 | Yes |
Application | linux-pam | linux-pam | 0.99.4.0 | Yes |
Application | linux-pam | linux-pam | 0.99.5.0 | Yes |
Application | linux-pam | linux-pam | 0.99.6.0 | Yes |
Application | linux-pam | linux-pam | 0.99.6.1 | Yes |
Application | linux-pam | linux-pam | 0.99.6.2 | Yes |
Application | linux-pam | linux-pam | 0.99.6.3 | Yes |
Application | linux-pam | linux-pam | 0.99.7.0 | Yes |
Application | linux-pam | linux-pam | 0.99.7.1 | Yes |
Application | linux-pam | linux-pam | 0.99.8.0 | Yes |
Application | linux-pam | linux-pam | 0.99.8.1 | Yes |
Application | linux-pam | linux-pam | 0.99.9.0 | Yes |
Application | linux-pam | linux-pam | 0.99.10.0 | Yes |
Application | linux-pam | linux-pam | 1.0.0 | Yes |
Application | linux-pam | linux-pam | 1.0.1 | Yes |
Application | linux-pam | linux-pam | 1.0.2 | Yes |
Application | linux-pam | linux-pam | 1.0.3 | Yes |