Trustix Apache-SSL RPM Permissions Vulnerability
BID:1575
Info
Trustix Apache-SSL RPM Permissions Vulnerability
| Bugtraq ID: | 1575 |
| Class: | Unknown |
| CVE: |
CVE-2000-0791 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 15 2000 12:00AM |
| Updated: | Jul 11 2009 02:56AM |
| Credit: | Posted to Bugtraq on August 15 2000 by Oystein Viggen of Trustix <[email protected]>. |
| Vulnerable: |
Trustix Trustix Secure Linux 1.1 |
| Not Vulnerable: | |
Discussion
Trustix Apache-SSL RPM Permissions Vulnerability
The RPM for Apache-SSL distributed with Trustix Secure Linux was misconfigured such that the httpsd binary installed world-writable by default. As the daemon runs as root, this could easily lead to privelege escalation for local users.
The RPM for Apache-SSL distributed with Trustix Secure Linux was misconfigured such that the httpsd binary installed world-writable by default. As the daemon runs as root, this could easily lead to privelege escalation for local users.
References
Trustix Apache-SSL RPM Permissions Vulnerability
References:
References: