Joined: 12 May 2004
|Posted: Wed Mar 11, 2009 12:26 am Post subject: [ GLSA 200903-24 ] Shadow: Privilege escalation
|Gentoo Linux Security Advisory
Title: Shadow: Privilege escalation (GLSA 200903-24)
Date: March 10, 2009
An insecure temporary file usage in Shadow may allow local users to gain root privileges.
Shadow is a set of tools to deal with user accounts.
Vulnerable: < 184.108.40.206
Unaffected: >= 220.127.116.11
Architectures: All supported architectures
Paul Szabo reported a race condition in the "login" executable when setting up tty permissions.
A local attacker belonging to the "utmp" group could use symlink attacks to overwrite arbitrary files and possibly gain root privileges.
There is no known workaround at this time.
All Shadow users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=sys-apps/shadow-18.104.22.168"