Opened 16 years ago

Closed 16 years ago

#2287 closed enhancement (fixed)

Shadow-4.1.2.2

Reported by: Matthew Burgess Owned by: lfs-book@…
Priority: normal Milestone: 7.0
Component: Book Version: SVN
Severity: normal Keywords:
Cc:

Description

Typical. This fixes a "race condition" vulnerability in login, which could lead to gaining ownership or changing mode of arbitrary files; and a possible login DOS when an attacker can inject forged entries in utmp.

Probably needs to be targetted for an errata announcement for 6.4, and then promoted to trunk for 7.0.

Change History (1)

comment:1 by Matthew Burgess, 16 years ago

Resolution: fixed
Status: newclosed

Fixed in r8767.

Note: See TracTickets for help on using tickets.