Improper Privilege Dropping in cmd5checkpw Allows Local File Read

Improper Privilege Dropping in cmd5checkpw Allows Local File Read

CVE-2005-0580 · LOW Severity

AV:L/AC:L/AU:N/C:P/I:N/A:N

cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.

Learn more about our User Device Pen Test.