Family: Debian Local Security Checks --> Category: infos
[DSA585] DSA-585-1 shadow Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
A vulnerability has been discovered in the shadow suite which provides
programs like chfn and chsh. It is possible for a user, who is logged
in but has an expired password to alter his account information with
chfn or chsh without having to change the password. The problem was
originally thought to be more severe.
For the stable distribution (woody) this problem has been fixed in
For the unstable distribution (sid) this problem has been fixed in
We recommend that you upgrade your passwd package (from the shadow
Solution : http://www.debian.org/security/2004/dsa-585
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.