HIGH · 7.2

CVE-2004-2396

passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM.

Vulnerability Description

passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MandrakesoftMandrake Multi Network Firewall8.2
MandrakesoftMandrake Linux8.2
MandrakesoftMandrake Linux Corporate Server2.1

References

FAQ

What is CVE-2004-2396?

CVE-2004-2396 is a vulnerability with a CVSS score of 7.2 (HIGH). passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM.

How severe is CVE-2004-2396?

CVE-2004-2396 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2396?

Check the references section above for vendor advisories and patch information. Affected products include: Mandrakesoft Mandrake Multi Network Firewall, Mandrakesoft Mandrake Linux, Mandrakesoft Mandrake Linux Corporate Server.