[318] in linux-security and linux-alert archive

home help back first fref pref prev next nref lref last post

passwd problem

daemon@ATHENA.MIT.EDU (Olaf Kirch)
Sat Aug 12 14:19:43 1995

From: okir@monad.swb.de (Olaf Kirch)
To: linux-security@tarsier.cv.nrao.edu
Date: Wed, 9 Aug 1995 09:49:05 +0200 (MET DST)

Hello,

I just came across a problem with the passwd command in utils-2.2. When
updating a user entry, it basically copies the passwd file to ptmp line
by line, and replaces the user's line if it thinks it had found it. The
problem is it just checks whether the line starts with the user name. So
if you change the password of user `www', you will completely wipe out
the entry for `wwwadmin'.

Older versions of passwd do not suffer from this problem, and according
to Rik Faith, it's fixed in the latest version (2.4).

Cheers
Olaf
- -- 
Olaf Kirch         |  --- o --- Nous sommes du soleil we love when we play
okir@monad.swb.de  |    / | \   sol.dhoop.naytheet.ah kin.ir.samse.qurax
             For my PGP public key, finger okir@brewhq.swb.de.

home help back first fref pref prev next nref lref last post