Bug#360657: passwd SIGSEGV on empty password

2006-04-04 Thread Moritz Muehlenhoff
Matteo Croce wrote: > Package: passwd > Version: 1:4.0.14-9 > Severity: critical > Tags: security > Justification: root security hole > > Just press ^D instead of the new password and passwd will segfaults. > I think that this is grave because it's set uid root. > > $ passwd > Changing password f

Bug#360657: passwd SIGSEGV on empty password

2006-04-03 Thread dann frazier
On Mon, Apr 03, 2006 at 10:59:32PM +0200, Matteo Croce wrote: > Package: passwd > Version: 1:4.0.14-9 > Severity: critical > Tags: security > Justification: root security hole > > Just press ^D instead of the new password and passwd will segfaults. > I think that this is grave because it's set uid

Bug#360657: passwd SIGSEGV on empty password

2006-04-03 Thread Steve Kemp
On Mon, Apr 03, 2006 at 10:59:32PM +0200, Matteo Croce wrote: > Package: passwd > Version: 1:4.0.14-9 > Severity: critical > Tags: security > Justification: root security hole > > Just press ^D instead of the new password and passwd will segfaults. > I think that this is grave because it's set uid

Bug#360657: passwd SIGSEGV on empty password

2006-04-03 Thread Matteo Croce
Package: passwd Version: 1:4.0.14-9 Severity: critical Tags: security Justification: root security hole Just press ^D instead of the new password and passwd will segfaults. I think that this is grave because it's set uid root. $ passwd Changing password for matteo (current) UNIX password: Enter n