util-linux: file name collision
| Package(s): | util-linux | CVE #(s): | CVE-2015-5224 | ||||
| Created: | September 9, 2015 | Updated: | September 10, 2015 | ||||
| Description: | From the Mageia advisory:
The chfn and chsh commands in util-linux's login-utils are vulnerable to a file name collision due to incorrect mkstemp usage. If the chfn and chsh binaries are both setuid-root they eventually call mkostemp in such a way that an attacker could repeatedly call them and eventually be able to overwrite certain files in /etc | ||||||
| Alerts: |
| ||||||
