|
|
|
![]() |
Vulnerability Note VU#801526util-linux login program discloses sensitive informationOverviewutil-linux login program uses a pointer that was previously freed and reallocated which could allow an attacker to gain access to sensitive information.I. Descriptionutil-linux is shipped with Red Hat and numerous other Linux distributions. It contains a collection of utility programs, such as fstab, mkfs, chfn, and login. There is a vulnerability in the way the login program uses a pointer that was previously freed and reallocated resulting in an information leak. This could be used by an attacker to gain access to sensitive information.II. ImpactAn attacker may be able to gain access to sensitive information.III. SolutionApply PatchApply a patch from your vendor.
References
Red Hat credits Matthew Lee for reporting this vulnerability. This document was written by Damon Morda.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||