[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2164-1 shadow -- insufficient input sanitization

ID: oval:org.secpod.oval:def:600198Date: (C)2011-03-10   (M)2022-10-10
Class: PATCHFamily: unix




Kees Cook discovered that the chfn and chsh utilities do not properly sanitize user input that includes newlines. An attacker could use this to to corrupt passwd entries and may create users or groups in NIS environments. Packages in the oldstable distribution are not affected by this problem.

Platform:
Debian 6.0
Product:
login
passwd
Reference:
DSA-2164-1
CVE-2011-0721
CVE    1
CVE-2011-0721
CPE    3
cpe:/o:debian:debian_linux:6.x
cpe:/a:debian:passwd
cpe:/a:debian:login

© SecPod Technologies