RedHat Single User Mode Authentication Vulnerability
BID:1005
Info
RedHat Single User Mode Authentication Vulnerability
| Bugtraq ID: | 1005 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2000-0219 |
| Remote: | No |
| Local: | No |
| Published: | Feb 23 2000 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | This vulnerability was posted to the Bugtraq mailing list by Darren Reed <[email protected]> |
| Vulnerable: |
Redhat Linux 6.0 |
| Not Vulnerable: | |
Discussion
RedHat Single User Mode Authentication Vulnerability
A vulnerability exists in the manner in which RedHat Linux 6.0 protects the obtaining of a shell by booting single user mode. RedHat will prompt for the root password upon entering single user mode. Pressing ^C (causing a SIGINT to be sent) immediately results in a root shell being made available.
A vulnerability exists in the manner in which RedHat Linux 6.0 protects the obtaining of a shell by booting single user mode. RedHat will prompt for the root password upon entering single user mode. Pressing ^C (causing a SIGINT to be sent) immediately results in a root shell being made available.
Exploit / POC
RedHat Single User Mode Authentication Vulnerability
boot single user from lilo, and press ^C (control-C)
boot single user from lilo, and press ^C (control-C)
Solution / Fix
RedHat Single User Mode Authentication Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Upgrading to versions of RedHat post 6.0 will correct this problem.
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Upgrading to versions of RedHat post 6.0 will correct this problem.
References
RedHat Single User Mode Authentication Vulnerability
References:
References:
- Updates, Fixes, and Errata Page (RedHat)