CVE-2014-3851 Information

Description

usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db which allows local users to obtain the administrator password by reading this file.

Reference

http://www.openwall.com/lists/oss-security/2014/05/14/3 http://www.openwall.com/lists/oss-security/2014/05/23/1

Share on: