CVE-2004-1001

NameCVE-2004-1001
DescriptionUnknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-585-1
NVD severitymedium (attack range: local)
Debian Bugs309587

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
shadow (PTS)wheezy1:4.1.5.1-1fixed
wheezy (security)1:4.1.5.1-1+deb7u1fixed
jessie (security), jessie1:4.2-3+deb8u4fixed
stretch1:4.4-4.1fixed
buster, sid1:4.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
shadowsource(unstable)1:4.0.3-35medium
shadowsourcesarge1:4.0.3-31sarge5medium309587
shadowsourcewoody20000902-12woody1mediumDSA-585-1

Notes

Fixed in 	shadow 1:4.0.3-30.3 for the first time.
Apparently, the fix was lost somehow, see #309587.
It was reapplied to sarge before the release, and to sid in
version 1:4.0.3-35.

Search for package or bug name: Reporting problems