An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
https://security-tracker.debian.org/tracker/CVE-2012-6655
https://exchange.xforce.ibmcloud.com/vulnerabilities/95325
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-6655