vipw in the util-linux package before 2.10 causes /etc/shadow to be world-readable in some cases, which would make it easier for local users to perform brute force password guessing.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6851 | vdb entry |
http://www.securityfocus.com/bid/3036 | vdb entry patch vendor advisory |
http://www.redhat.com/support/errata/RHSA-2001-132.html | vendor advisory |
http://www.redhat.com/support/errata/RHSA-2001-095.html | patch vendor advisory |