Caldera Open Administration System Vulnerability
BID:137
Info
Caldera Open Administration System Vulnerability
| Bugtraq ID: | 137 |
| Class: | Configuration Error |
| CVE: |
CVE-1999-0712 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 26 1999 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | This advisory was posted to the Caldera on April 27th/1999. |
| Vulnerable: |
Caldera coas 1.0 -7 Caldera coas 1.0 -6 Caldera coas 1.0 -5 |
| Not Vulnerable: |
Caldera coas 1.0 -8 |
Discussion
Caldera Open Administration System Vulnerability
April 27th/1999 Caldera Systems released a vague advisory in relation to the Caldera Open Administration System previous to version 1.0-8. The advisory indicate that in some instances the Administration System leaves the /etc/shadow directory which contains the password hashes for the system users, world readable.
April 27th/1999 Caldera Systems released a vague advisory in relation to the Caldera Open Administration System previous to version 1.0-8. The advisory indicate that in some instances the Administration System leaves the /etc/shadow directory which contains the password hashes for the system users, world readable.
Exploit / POC
Caldera Open Administration System Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Caldera Open Administration System Vulnerability
Solution:
The proper solution is to upgrade to the coas-1.0-8 package. If /etc/shadow is world-readable, this is fixed with
chmod 600 /etc/shadow
The upgrade packages can be found on Caldera's FTP site at:
ftp://ftp.calderasystems.com/pub/OpenLinux/updates/2.2/current/RPMS/
The corresponding source code package can be found at:
ftp://ftp.calderaystems.com/pub/OpenLinux/updates/2.2/current/SRPMS
Solution:
The proper solution is to upgrade to the coas-1.0-8 package. If /etc/shadow is world-readable, this is fixed with
chmod 600 /etc/shadow
The upgrade packages can be found on Caldera's FTP site at:
ftp://ftp.calderasystems.com/pub/OpenLinux/updates/2.2/current/RPMS/
The corresponding source code package can be found at:
ftp://ftp.calderaystems.com/pub/OpenLinux/updates/2.2/current/SRPMS
References
Caldera Open Administration System Vulnerability
References:
References: