« List of all CVEs

CVE-2008-1946

Published: 7/28/2008 Last updated: 8/7/2024 Reserved: 4/24/2008

The default configuration of su in /etc/pam.d/su in GNU coreutils 5.2.1 allows local users to gain the privileges of a (1) locked or (2) expired account by entering the account name on the command line, related to improper use of the pam_succeed_if.so module.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (5)

conf-timeout fstar karamel kremlin liquidsoap

Products affected (1)

Product Vendor Version
n/a n/a 7.2(1)

References (12)