modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-03-12 16:55
Updated : 2013-03-19 05:35
NVD link : CVE-2011-4966
Mitre link : CVE-2011-4966
JSON object : View
CWE
CWE-255
Credentials Management Errors
Products Affected
freeradius
- freeradius