CVE-2004-1001

NameCVE-2004-1001
DescriptionUnknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-585-1
NVD severitymedium (attack range: local)
Debian Bugs309587

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
shadow (PTS)jessie, jessie (security)1:4.2-3+deb8u4fixed
stretch1:4.4-4.1fixed
buster, sid1:4.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
shadowsource(unstable)1:4.0.3-35medium
shadowsourcesarge1:4.0.3-31sarge5medium309587
shadowsourcewoody20000902-12woody1mediumDSA-585-1

Notes

Fixed in 	shadow 1:4.0.3-30.3 for the first time.
Apparently, the fix was lost somehow, see #309587.
It was reapplied to sarge before the release, and to sid in
version 1:4.0.3-35.

Search for package or bug name: Reporting problems