[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

USN-732-1 -- dash vulnerability

ID: oval:org.secpod.oval:def:700427Date: (C)2011-05-13   (M)2021-06-02
Class: PATCHFamily: unix




Wolfgang M. Reimer discovered that dash, when invoked as a login shell, would source .profile files from the current directory. Local users may be able to bypass security restrictions and gain root privileges by placing specially crafted .profile files where they might get sourced by other dash users.

Platform:
Ubuntu 8.10
Ubuntu 8.04
Product:
dash
Reference:
USN-732-1
CVE-2009-0854
CVE    1
CVE-2009-0854
CPE    2
cpe:/o:ubuntu:ubuntu_linux:8.04
cpe:/o:ubuntu:ubuntu_linux:8.10

© SecPod Technologies