SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#312692

Shadow Utils useradd utility sets incorrect file permissions

Overview

The Shadow Utilities contain a vulnerability that may result in new user mailboxes having arbitrary permissions.

I. Description

The Shadow Utilities provide tools to manage user accounts.

When a new mailbox is created using the useradd utility, the open() function does not receive the expected arguments while O_CREAT is present. The result of this error is that random permissions are applied to the new mailbox.

II. Impact

A local, unprivileged attacker may be able to gain access to newly created mailbox files.

III. Solution

Affected vendors have released updates to address this issue. Users are encouraged to see the Systems Affected portion of this document for a partial list of affected vendors.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Not Vulnerable23-May-2006
Cisco Systems, Inc.Unknown12-May-2006
Conectiva Inc.Unknown17-May-2006
Cray Inc.Unknown17-May-2006
Debian GNU/LinuxUnknown17-May-2006
EMC, Inc. (formerly Data General Corporation)Unknown17-May-2006
Engarde Secure LinuxUnknown17-May-2006
F5 Networks, Inc.Not Vulnerable22-May-2006
Fedora ProjectUnknown17-May-2006
FreeBSD, Inc.Unknown17-May-2006
FujitsuUnknown17-May-2006
Gentoo LinuxVulnerable14-Dec-2007
Hewlett-Packard CompanyUnknown17-May-2006
HitachiUnknown17-May-2006
IBM CorporationUnknown17-May-2006
IBM Corporation (zseries)Unknown17-May-2006
IBM eServerUnknown17-May-2006
Immunix Communications, Inc.Unknown17-May-2006
Ingrian Networks, Inc.Unknown17-May-2006
Juniper Networks, Inc.Unknown17-May-2006
Mandriva, Inc.Unknown17-May-2006
Microsoft CorporationUnknown17-May-2006
MontaVista Software, Inc.Unknown17-May-2006
NEC CorporationUnknown17-May-2006
NetBSDUnknown17-May-2006
NokiaUnknown17-May-2006
Novell, Inc.Unknown17-May-2006
OpenBSDUnknown17-May-2006
Openwall GNU/*/LinuxNot Vulnerable17-May-2006
QNX, Software Systems, Inc.Unknown17-May-2006
Red Hat, Inc.Unknown12-May-2006
Silicon Graphics, Inc.Unknown17-May-2006
Slackware Linux Inc.Unknown17-May-2006
Sony CorporationUnknown17-May-2006
Sun Microsystems, Inc.Unknown17-May-2006
SUSE LinuxUnknown17-May-2006
Trustix Secure LinuxUnknown17-May-2006
TurbolinuxUnknown17-May-2006
UbuntuUnknown17-May-2006
UnisysUnknown17-May-2006
Wind River Systems, Inc.Unknown17-May-2006

References


http://linux.die.net/man/8/useradd
http://www.redhat.com/docs/manuals/enterprise/RHEL-5-manual/Deployment_Guide-en-US/s1-users-tools.html
http://www.gentoo.org/security/en/glsa/glsa-200606-02.xml
http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/shadow-utils/shadow-4.0.4.1-owl-create-mailbox.diff?rev=HEAD
http://www.securityfocus.com/archive/1/archive/1/468336/100/0/threaded
https://www.securecoding.cert.org/confluence/x/VQBc

Credit

This document was written by Jeff Gennari.

Other Information

Date Public:2006-05-31
Date First Published:2007-12-14
Date Last Updated:2007-12-14
CERT Advisory: 
CVE-ID(s):CVE-2006-1174
NVD-ID(s):CVE-2006-1174
US-CERT Technical Alerts: 
Metric:0.23
Document Revision:27

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader