|
|
|
![]() |
Vulnerability Note VU#424080shadow-utils useradd creates temporary files insecurelyOverviewShadow-utils is an encryption and account management package freely distributed for many Linux implementations. The useradd program in this package creates insecure temporary files with predictable names in a write-protected directory. If this directory is changed to be writable, an attacker may be able to use a symbolic link attack to overwrite arbitrary files.I. DescriptionThe useradd program calls the passwd program, which stores temporary files with predictable names in /etc/default, a protected directory. The program does not check for prior existence or ownership of these files. Useradd normally runs with setuid root privileges.II. ImpactIf /etc/default is changed to be world-writable, an attacker may be able to create a symbolic link with predictable name, and point it to any writable file on the system. This may cause corruption of the file.III. SolutionApply vendor patches; see the Systems Affected section below.Change /etc/default to not be world-writable.
Referenceshttp://www.securityfocus.com/bid/2196 This vulnerability was first reported by Greg Kroah-Hartman This document was last modified by Tim Shimeall.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||