Revision Date: | 2004-05-26 | Version: | 502 |
Title: | RHSA-2004:174: utempter security update (Moderate) |
Description: | Utempter is a utility that allows terminal applications such as xterm and screen to update utmp and wtmp without requiring root privileges.
Steve Grubb discovered a flaw in Utempter which allowed device names containing directory traversal sequences such as '/../'. In combination with an application that trusts the utmp or wtmp files, this could allow a local attacker the ability to overwrite privileged files using a symlink.
Users should upgrade to this new version of utempter, which fixes this vulnerability.
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | CVE-2004-0233 RHSA-2004:174-01
|
Platform(s): | Red Hat Enterprise Linux 3
| Product(s): | |
Definition Synopsis |
Red Hat Enterprise Linux 3 is installed AND utempter is earlier than 0:0.5.5-1.3EL.0
AND utempter is signed with Red Hat master key
|