Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2003:026: shadow-utils Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the shadow-utils package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2003:026 (shadow-utils).
The shadow-utils package contains the tool useradd, which is used to create or
update new user information. When useradd creates an account, it would create it
with improper permissions
instead of having it owned by the group mail, it
would be owned by the user's primary group. If this is a shared group (ie.
'users'), then all members of the shared group would be able to obtain access to
the mail spools of other members of the same group. A patch to useradd has been
applied to correct this problem.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:026
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.