FreeBSD rmuser Password Hash Disclosure Vulnerability
BID:3282
Info
FreeBSD rmuser Password Hash Disclosure Vulnerability
| Bugtraq ID: | 3282 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 04 2001 12:00AM |
| Updated: | Sep 04 2001 12:00AM |
| Credit: | Credited to <[email protected]>. |
| Vulnerable: |
FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 |
| Not Vulnerable: | |
Discussion
FreeBSD rmuser Password Hash Disclosure Vulnerability
FreeBSD ships with a perl script called 'rmuser'. It can be used by administrators to completely remove users from a system.
The rmuser script temporarily creates a world readable copy of 'master.passwd'. If an attacker can anticipate the use of rmuser by an administrator, it may be possible to obtain the contents of 'master.passwd'.
Exploitation of this vulnerability is extremely time-dependent.
FreeBSD ships with a perl script called 'rmuser'. It can be used by administrators to completely remove users from a system.
The rmuser script temporarily creates a world readable copy of 'master.passwd'. If an attacker can anticipate the use of rmuser by an administrator, it may be possible to obtain the contents of 'master.passwd'.
Exploitation of this vulnerability is extremely time-dependent.
Exploit / POC
FreeBSD rmuser Password Hash Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
FreeBSD rmuser Password Hash Disclosure Vulnerability
References:
References:
- FreeBSD Security Information (FreeBSD)