Debian Security Advisory
DLA-191-1 checkpw -- LTS security update
- Date Reported:
- 09 Apr 2015
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2015-0885.
- More information:
Hiroya Ito of GMO Pepabo, Inc. reported that checkpw, a password authentication program, has a flaw in processing account names which contain double dashes. A remote attacker can use this flaw to cause a denial of service (infinite loop).
Thanks to Markus Koschany who prepared the Debian package.