|
|
| |
|
| |
shadow: privilege escalation
| Package(s): | shadow |
CVE #(s): | CVE-2008-5394
|
| Created: | January 21, 2009 |
Updated: | March 11, 2009 |
| Description: |
From the Debian advisory:
Paul Szabo discovered that login, the system login tool, did not
correctly handle symlinks while setting up tty permissions. If a local
attacker were able to gain control of the system utmp file, they could
cause login to change the ownership and permissions on arbitrary files,
leading to a root privilege escalation.
|
| Alerts: |
|
( Log in to post comments)
|
|
|