Vipw Insecure File Permissions Vulnerability
BID:3036
Info
Vipw Insecure File Permissions Vulnerability
| Bugtraq ID: | 3036 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 12 2001 12:00AM |
| Updated: | Jul 12 2001 12:00AM |
| Credit: | Reportedly discovered by [email protected] and published in a RedHat Security Advisory on July 12, 2001. |
| Vulnerable: |
Redhat util-linux-2.10s-12.i386.rpm Andries Brouwer util-linux 2.11 d Andries Brouwer util-linux 2.10 s |
| Not Vulnerable: | |
Discussion
Vipw Insecure File Permissions Vulnerability
Vipw is an editing application used for system password and group files.
Some versions of the 'vipw' program fail to correctly set the permissions of the '/etc/shadow' file after editing it. The permissions of the file are changed to be world-readable, thus allowing any local user to read its contents. This may lead to a system compromise.
Vipw is an editing application used for system password and group files.
Some versions of the 'vipw' program fail to correctly set the permissions of the '/etc/shadow' file after editing it. The permissions of the file are changed to be world-readable, thus allowing any local user to read its contents. This may lead to a system compromise.
Exploit / POC
Vipw Insecure File Permissions Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.