LWN.net Logo

shadow: privilege escalation

Package(s):shadow CVE #(s):CVE-2008-5394
Created:January 21, 2009 Updated:March 11, 2009
Description:

From the Debian advisory:

Paul Szabo discovered that login, the system login tool, did not correctly handle symlinks while setting up tty permissions. If a local attacker were able to gain control of the system utmp file, they could cause login to change the ownership and permissions on arbitrary files, leading to a root privilege escalation.

Alerts:
Gentoo 200903-24 2009-03-10
Mandriva MDVSA-2009:062 2008-03-02
Debian DSA-1709-1 2009-01-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds