SUSE-SA:2005:064: pwdutils, shadow

high Nessus Plugin ID 20209

Synopsis

The remote host is missing a vendor-supplied security patch

Description

The remote host is missing the patch for the advisory SUSE-SA:2005:064 (pwdutils, shadow).


Thomas Gerisch found that the setuid 'chfn' program contained in the pwdutils suite insufficiently checks it's arguments when changing the GECOS field. This bug leads to a trivially exploitable local privilege escalation that allows users to gain root access.

We like to thank Thomas Gerisch for pointing out the problem.

Solution

http://www.suse.de/security/advisories/2005_64_pwdutils.html

Plugin Details

Severity: High

ID: 20209

File Name: suse_SA_2005_064.nasl

Version: 1.9

Agent: unix

Published: 11/15/2005

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Vulnerability Information

Required KB Items: Host/SuSE/rpm-list