passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16179
http://www.securityfocus.com/bid/10370
http://www.mandriva.com/security/advisories?name=MDKSA-2004:045