This checkpass may be safely installed setuid root - it drops any
priviledges when it's to run any application (it tries to exec argv[1]
when specified, as stated in CHECKPASSWORD standard).
As root it does only parse stream from file descriptor 3, and setuids to
user named in "login" field, to check if password is valid.
For more information, see CHECKPASSWORD documentation.
