Advertisement
Home arrow ITsec Advisories arrow [GLSA 200606-02] shadow: Privilege escalation
Saturday, 22 November 2008
 
 
Last week attacks
O.S.  Defs.  %
Linux  8778  71.58%
Win 2003  1950  15.90%
Win 2000  722  5.89%
Solaris 9/10  402  3.28%
FreeBSD  226  1.84%
Other  185  1.51%

Total attacks: 12263 of which 4619 single ip and 7644 mass defacements

Main Menu
Home
Digital Warfare
Geopolitics
ITsec News
ITsec Advisories
Test Drive
360°
Digital Attacks Archive
Zone-H events
Publications
Zone-H Friends/Partners
Contact Us
Search
Download Area
Zone-H forum
About this website
Login Form





Lost Password?
No account yet? Register
Visitors' Map
[GLSA 200606-02] shadow: Privilege escalation PDF Print E-mail
User Rating: / 0
PoorBest 
Wednesday, 07 June 2006

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200606-02
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

      Severity: Normal
      Title: shadow: Privilege escalation
      Date: June 07, 2006
      Bugs: #133615
      ID: 200606-02

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
======

A security issue in shadow allows a local user to perform certain
actions with escalated privileges.


Background
=======

shadow provides a set of utilities to deal with user accounts.

 

Affected packages
============

    -------------------------------------------------------------------
     Package / Vulnerable / Unaffected
    -------------------------------------------------------------------
  1 sys-apps/shadow < 4.0.15-r2 >= 4.0.15-r2

 

Description
=======

When the mailbox is created in useradd, the "open()" function does not
receive the three arguments it expects while O_CREAT is present, which
leads to random permissions on the created file, before fchmod() is
executed.

 

Impact
====

Depending on the random permissions given to the mailbox file which is
at this time owned by root, a local user may be able to open this file
for reading or writing, or even executing it, maybe as the root user.

 

Workaround
=======

There is no known workaround at this time.

 

Resolution
======

All shadow users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=sys-apps/shadow-4.0.15-r2"

 

References
=======

  [ 1 ] CVE-2006-1174
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1174

 

Availability
======

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

  http://security.gentoo.org/glsa/glsa-200606-02.xml

 

Concerns?
======

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security_at_gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.

 

License
=====

Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5

 



Original Advisory:
http://seclists.org/lists/fulldisclosure/2006/Jun/0184.html  

 

 


Comments Index (Total Messages: 0)


Post Reply
Name:Guest
Title:
Comment:



Enter this security word

Powered by a Zone-H(ified) version of AkoComment 3.0!


DISCLAIMER: Forum postings are the opinion of the posting author alone, and should not be taken as the opinion of Zone-h. The   author is entirely and solely responsible for all content that he/she uploads, posts, or otherwise transmits via the website. Zone-h is not responsible for such content. However, Zone-h shall have the right, but not the obligation, to delete, move, or edit any content that violates this agreement or is otherwise objectionable as determined by Zone-h in its sole discretion and without notice.
 
< Prev   Next >
 
Top! Top!