|
|
|
Vulnerability Note VU#982616
KDE2 kdesu 'keep password' option does not verify socket listener potentially exposing su password
Overviewkdesu is a interactive interface to the substitute user (su) command for the KDE environment. To pass authentication information, it creates a file that may be read by unauthorized users.
I. Descriptionkdesu communicates with su using a socket, implemented as a file in /tmp with a predictable name. In this file is placed authenticating information for the effective user that the kdesu user wishes to become (often root).II. ImpactBy using a symbolic link attack, an attacker may be able to capture usernames and passwords.III. SolutionApply vendor patches; see the Systems Affected section below.
Creating files in /tmp with appropriate names may block the symbolic link attack, but it may also prevent kdesu from operating properly. It will not be a robust fix.
Systems Affected
References
http://www.calderasystems.com/support/security/advisories/CSSA-2001-005.0.txt
http://www.securityfocus.com/bid/2669
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-046.php3?dis=8.0
http://www.linuxsecurity.com/advisories/redhat_advisory-1335.html
http://www.linuxsecurity.com/advisories/other_advisory-1119.html
http://www.linuxsecurity.com/advisories/suse_advisory-1113.html
Credit
Initial information on this vulnerability came from a statement by Caldera Systems.
This document was last modified by Tim Shimeall.
Other Information
| Date Public | 01/23/2001 |
| Date First Published | 05/17/2001 02:37:34 PM |
| Date Last Updated | 08/01/2001 |
| CERT Advisory | |
| CVE Name | CAN-2001-0178 |
| Metric | 8.10 |
| Document Revision | 11 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |