The SCO Group (SCO Linux) Information for VU#405955

util-linux package vulnerable to privilege escalation when "ptmptmp" file is not removed properly when using "chfn" utility

Status

Affected

Vendor Statement

Caldera OpenLinux is vulnerable to this race condition, and we are preparing a fix.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References

None

Addendum

Please also see ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2002-043.0.txt.

If you have feedback, comments, or additional information about this vulnerability, please send us email.