{"id":"CVE-2009-0579","details":"Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.","modified":"2026-04-10T03:40:38.322113Z","published":"2009-04-16T15:12:57Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/34728"},{"type":"ADVISORY","url":"http://secunia.com/advisories/34733"},{"type":"ADVISORY","url":"https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00420.html"},{"type":"ADVISORY","url":"https://www.redhat.com/archives/pam-list/2009-March/msg00006.html"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=487216"},{"type":"FIX","url":"https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00420.html"},{"type":"WEB","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514437"},{"type":"WEB","url":"https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00398.html"}],"schema_version":"1.7.5"}