Back

MEDIUM

pam: MINDAYS not respected by pam for password changing

Published Apr 16, 2009

Description

Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of pam as shipped with Red Hat Enterprise Linux 3, 4, 5, or 6.

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 16, 2009
Updated Aug 7, 2024
Reserved Feb 13, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Feb 7, 2009