NeXTstep "me" account Vulnerability
BID:20
Info
NeXTstep "me" account Vulnerability
| Bugtraq ID: | 20 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 1991 12:00AM |
| Updated: | May 14 1991 12:00AM |
| Credit: | |
| Vulnerable: |
NeXT NeXTstep 2.1 NeXT NeXTstep 2.0 NeXT NeXTstep 1.0 a NeXT NeXTstep 1.0 |
| Not Vulnerable: | |
Discussion
NeXTstep "me" account Vulnerability
Username "me" is a member of the "wheel" group
in all NeXTstep versions through and including 2.1.
Having username "me" in the "wheel" group enables
"me" to use the su(8) command to become root (the user
must still know the root password, however).
Notice that the username "me" is created at installation time
with no password by default.
Username "me" is a member of the "wheel" group
in all NeXTstep versions through and including 2.1.
Having username "me" in the "wheel" group enables
"me" to use the su(8) command to become root (the user
must still know the root password, however).
Notice that the username "me" is created at installation time
with no password by default.
References
NeXTstep "me" account Vulnerability
References:
References: