Slackware World-Writable Valid Shell List Vulnerability
BID:2854
Info
Slackware World-Writable Valid Shell List Vulnerability
| Bugtraq ID: | 2854 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 24 2000 12:00AM |
| Updated: | Aug 24 2000 12:00AM |
| Credit: | This vulnerability was fixed in Slackware-current on August 24, 2000. |
| Vulnerable: |
Slackware Linux 7.1 |
| Not Vulnerable: | |
Discussion
Slackware World-Writable Valid Shell List Vulnerability
A vulnerability exists in Slackware Linux version 7.1.
During the default installation of Slackware Linux, the /etc/shells file is installed with world-writable permissions. As a result, it may be possible for local users to modify this file and effectively cause a denial of service to users attempting to use applications which rely on the data contained in the file.
A vulnerability exists in Slackware Linux version 7.1.
During the default installation of Slackware Linux, the /etc/shells file is installed with world-writable permissions. As a result, it may be possible for local users to modify this file and effectively cause a denial of service to users attempting to use applications which rely on the data contained in the file.
Solution / Fix
Slackware World-Writable Valid Shell List Vulnerability
Solution:
This issue has been resolved in the base.tgz package in the Slackware-current tree as of August 24, 2000.
Solution:
This issue has been resolved in the base.tgz package in the Slackware-current tree as of August 24, 2000.
References
Slackware World-Writable Valid Shell List Vulnerability
References:
References: