CVE-2004-1001

NameCVE-2004-1001
DescriptionUnknown vulnerability in the passwd_check function in Shadow 4.0.4.1, ...
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-585-1
Debian Bugs309587

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
shadow (PTS)buster1:4.5-1.1fixed
bullseye1:4.8.1-1fixed
bookworm, sid1:4.11.1+dfsg1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
shadowsourcewoody20000902-12woody1DSA-585-1
shadowsourcesarge1:4.0.3-31sarge5309587
shadowsource(unstable)1:4.0.3-35

Notes

Fixed in shadow 1:4.0.3-30.3 for the first time.
Apparently, the fix was lost somehow, see #309587.
It was reapplied to sarge before the release, and to sid in
version 1:4.0.3-35.

Search for package or bug name: Reporting problems