Local root vulnerability in chfn
| Package(s): | util-linux | CVE #(s): | CAN-2002-0638 | ||||||||||||||||||||||||||||
| Created: | July 30, 2002 | Updated: | October 31, 2002 | ||||||||||||||||||||||||||||
| Description: | chfn (change finger information) is one of the utilities in
the util-linux package.
The BindView RAZOR Team has discovered a local root vulnerability
in chfn which is described in the Bindview Advisory.
Under certain conditions, "a carefully crafted attack sequence can be performed to exploit a complex file locking and modification race present in this utility, and, as a result, alter /etc/passwd to escalate privileges in the system." The conditions include a password file, /etc/passwd, over 4 kilobytes and locating the attacker's account record in any but the last 4 kB chunk of the file. CERT/CC Vulnerability Note VU#405955 util-linux package vulnerable to privilege escalation when "ptmptmp" file is not removed properly when using "chfn" utility | ||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||
