CVE-2023-4641

ADVISORY - nist

Summary

A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.

EPSS Score: 0.00015 (0.025)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Authentication

Incorrect Implementation of Authentication Algorithm

ADVISORY - redhat

Incorrect Implementation of Authentication Algorithm


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in