LWN.net Logo

systemd: removal of arbitrary system files

Package(s):systemd CVE #(s):CVE-2012-1174
Created:March 19, 2012 Updated:March 26, 2012
Description: From the Mandriva advisory:

A TOCTOU race condition was found in the way the systemd-logind login manager performed removal of particular records related with user session upon user logout. A local attacker could use this flaw to conduct symbolic link attacks, potentially leading to removal of arbitrary system files.

Alerts:
Mandriva MDVSA-2012:030 2012-03-16
openSUSE openSUSE-SU-2012:0383-1 2012-03-19
Fedora FEDORA-2012-4018 2012-03-26
Fedora FEDORA-2012-4024 2012-03-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds