← Back

CVE-2011-4966

nvd nist
Published: Mar 12, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.0
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Exploitability: 6.8 / Impact: 6.4
Source: NVD

Description

modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.

Affected (50)

1 product
Freeradius
Configuration A
50 vulnerable
Vulnerable SoftwareAffected Versions
Freeradius
All versions
Up to 2.2.0
Version 0.1
Version 0.2
Version 0.3
Version 0.4
Version 0.5
Version 0.6
Version 0.7.1
Version 0.7
Version 0.8.1
Version 0.8
Version 0.9.0
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.1.0
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1.6
Version 1.1.7
Version 1.1.8
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0
Version 2.1.0
Version 2.1.10
Version 2.1.11
Version 2.1.12
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.6
Version 2.1.7
Version 2.1.8
Version 2.1.9

Related CWEs

Timeline

No history available yet.