Mandrake Linux passwd Potential Vulnerabilities
BID:10370
Info
Mandrake Linux passwd Potential Vulnerabilities
| Bugtraq ID: | 10370 |
| Class: | Unknown |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | May 17 2004 12:00AM |
| Updated: | May 17 2004 12:00AM |
| Credit: | Issues reported to Mandrake by Steve Grubb. |
| Vulnerable: |
Mandriva Linux Mandrake 10.0 Mandriva Linux Mandrake 9.2 amd64 Mandriva Linux Mandrake 9.2 Mandriva Linux Mandrake 9.1 ppc Mandriva Linux Mandrake 9.1 Mandriva Linux Mandrake 9.0 Mandriva Linux Mandrake 8.2 ppc Mandriva Linux Mandrake 8.2 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 |
| Not Vulnerable: | |
Discussion
Mandrake Linux passwd Potential Vulnerabilities
Two potential security issues reportedly affect the implementation of passwd included with Mandrake Linux, according to Mandrake advisory MDKSA-2004:045. According to the report, passwords supplied to passwd via stdin are incorrectly one character shorter than they should be. It is not known whether this behavior occurs at the interactive prompt or if the implementation allows for passwords to be "piped" to passwd through stdin. This may or may not have security implications as the user's password will not be stored correctly and the user will not be able to login. It is conceivable that this could result in a less secure password. The second issue reported by Mandrake is that PAM may not be initialized correctly and "safe and proper" operation may not be ensured. Further technical details are not known.
Two potential security issues reportedly affect the implementation of passwd included with Mandrake Linux, according to Mandrake advisory MDKSA-2004:045. According to the report, passwords supplied to passwd via stdin are incorrectly one character shorter than they should be. It is not known whether this behavior occurs at the interactive prompt or if the implementation allows for passwords to be "piped" to passwd through stdin. This may or may not have security implications as the user's password will not be stored correctly and the user will not be able to login. It is conceivable that this could result in a less secure password. The second issue reported by Mandrake is that PAM may not be initialized correctly and "safe and proper" operation may not be ensured. Further technical details are not known.
Exploit / POC
Mandrake Linux passwd Potential Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Mandrake Linux passwd Potential Vulnerabilities
Solution:
Mandrake has issued advisory MDKSA-2004:045 and fixes. See link in the reference section for more information.
Solution:
Mandrake has issued advisory MDKSA-2004:045 and fixes. See link in the reference section for more information.
References
Mandrake Linux passwd Potential Vulnerabilities
References:
References: