 |
|
|
Family: Slackware Local Security Checks --> Category: infos
SSA-2004-110-01 utempter security update Vulnerability Scan
Vulnerability Scan Summary SSA-2004-110-01 utempter security update
Detailed Explanation for this Vulnerability Test
New utempter packages are available for Slackware 9.1 and -current to
fix a security issue. (Slackware 9.1 was the first version of Slackware
to use the libutempter library, and earlier versions of Slackware are
not affected by this issue)
The utempter package provides a utility and shared library that
allows terminal applications such as xterm and screen to update
/var/run/utmp and /var/log/wtmp without requiring root rights.
Steve Grubb has identified an issue with utempter-0.5.2 where
under certain circumstances a possible hacker could cause it to
overwrite files through a symlink. This has been addressed by
upgrading the utempter package to use Dmitry V. Levin's new
implementation of libutempter that does not have this bug.
More details about this issue may be found in the Common
Vulnerabilities and Exposures (CVE) database:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0233
Click HERE for more information and discussions on this network vulnerability scan.
|
|
|
|
|