|
|
|
![]() |
Vulnerability Note VU#982616KDE2 kdesu 'keep password' option does not verify socket listener potentially exposing su passwordOverviewkdesu is a interactive interface to the substitute user (su) command for the KDE environment. To pass authentication information, it creates a file that may be read by unauthorized users.I. Descriptionkdesu communicates with su using a socket, implemented as a file in /tmp with a predictable name. In this file is placed authenticating information for the effective user that the kdesu user wishes to become (often root).II. ImpactBy using a symbolic link attack, an attacker may be able to capture usernames and passwords.III. SolutionApply vendor patches; see the Systems Affected section below.Creating files in /tmp with appropriate names may block the symbolic link attack, but it may also prevent kdesu from operating properly. It will not be a robust fix.
Referenceshttp://www.calderasystems.com/support/security/advisories/CSSA-2001-005.0.txt Initial information on this vulnerability came from a statement by Caldera Systems. This document was last modified by Tim Shimeall.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||