|
|
| |
|
| |
mod-auth-shadow: password expiration
| Package(s): | mod-auth-shadow |
CVE #(s): | CAN-2004-0041
|
| Created: | January 12, 2004 |
Updated: | January 14, 2004 |
| Description: |
David B Harris discovered a problem with mod-auth-shadow, an Apache module
which authenticates users against the system shadow password database,
where the expiration status of the user's account and password were not
enforced. This vulnerability would allow an otherwise authorized user to
successfully authenticate, when the attempt should be rejected due to the
expiration parameters. |
| Alerts: |
|
( Log in to post comments)
|
|
|