Mandrake Linux Security Advisory : util-linux (MDKSA-2002:047)
Medium Nessus Plugin ID 13950
SynopsisThe remote Mandrake Linux host is missing one or more security updates.
DescriptionMichal Zalewski found a vulnerability in the util-linux package with the chfn utility. This utility allows users to modify some information in the /etc/passwd file, and is installed setuid root. Using a carefully crafted attack sequence, an attacker can exploit a complex file locking and modification race that would allow them to make changes to the /etc/passwd file. To successfully exploit this vulnerability and obtain privilege escalation, there is a need for some administrator interaction, and the password file must over over 4kb in size; the attacker's entry cannot be in the last 4kb of the file.
SolutionUpdate the affected losetup, mount and / or util-linux packages.