An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2012-6655 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-6655 | issue tracking third party advisory |
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2012-6655 | issue tracking exploit third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95325 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2014/08/16/7 | third party advisory mailing list |
http://www.securityfocus.com/bid/69245 | vdb entry third party advisory |