CVE

Id
11786  
CVE No.
CVE-2005-0580  
Status
Candidate  
Description
cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.  
Phase
Assigned (20050227)  
Votes
None (candidate not yet proposed)  
Comments