Vulnerabilities > CVE-2001-1175 - Unspecified vulnerability in Andries Brouwer Util-Linux 2.10S/2.11D

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
andries-brouwer

Summary

vipw in the util-linux package before 2.10 causes /etc/shadow to be world-readable in some cases, which would make it easier for local users to perform brute force password guessing.

Vulnerable Configurations

Part Description Count
Application
Andries_Brouwer
2

Redhat

advisories
  • rhsa
    idRHSA-2001:095
  • rhsa
    idRHSA-2001:132