| [GLSA 200606-02] shadow: Privilege escalation |
|
|
|
| Wednesday, 07 June 2006 | |||||
|
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis A security issue in shadow allows a local user to perform certain Background shadow provides a set of utilities to deal with user accounts.
Affected packages -------------------------------------------------------------------
Description When the mailbox is created in useradd, the "open()" function does not
Impact Depending on the random permissions given to the mailbox file which is
Workaround There is no known workaround at this time.
Resolution All shadow users should upgrade to the latest version: # emerge --sync
References [ 1 ] CVE-2006-1174
Availability This GLSA and any updates to it are available for viewing at http://security.gentoo.org/glsa/glsa-200606-02.xml
Concerns? Security is a primary focus of Gentoo Linux and ensuring the
License Copyright 2006 Gentoo Foundation, Inc; referenced text The contents of this document are licensed under the http://creativecommons.org/licenses/by-sa/2.5
Original Advisory: http://seclists.org/lists/fulldisclosure/2006/Jun/0184.html
Powered by a Zone-H(ified) version of AkoComment 3.0! DISCLAIMER: Forum postings are the opinion of the posting author alone, and should not be taken as the opinion of Zone-h. The author is entirely and solely responsible for all content that he/she uploads, posts, or otherwise transmits via the website. Zone-h is not responsible for such content. However, Zone-h shall have the right, but not the obligation, to delete, move, or edit any content that violates this agreement or is otherwise objectionable as determined by Zone-h in its sole discretion and without notice. |
|||||
| < Prev | Next > |
|---|






