Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200404-06 ] Util-linux login may leak sensitive data
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Bodhisattva
Bodhisattva


Joined: 13 Jun 2003
Posts: 4087
Location: Dresden, Germany

PostPosted: Wed Apr 07, 2004 5:34 pm    Post subject: [ GLSA 200404-06 ] Util-linux login may leak sensitive data Reply with quote

Gentoo Linux Security Advisory

Title: Util-linux login may leak sensitive data (GLSA 200404-06)
Severity: low
Exploitable: remote
Date: April 07, 2004
Bug(s): #46422
ID: 200404-06

Synopsis

The login program included in util-linux could leak sensitive information under certain conditions.

Background

Util-linux is a suite of essential system utilites, including login, agetty, fdisk.

Affected Packages

Package: sys-apps/util-linux
Vulnerable: <= 2.11
Unaffected: >= 2.12
Architectures: All supported architectures


Description

In some situations the login program could leak sensitive data due to an incorrect usage of a reallocated pointer. NOTE: Only users who have PAM support disabled on their systems (i.e. -PAM in their USE variable) will be affected by this vulnerability. By default, this USE flag is enabled on all architectures. Users with PAM support on their system receive login binaries as part of the pam-login package, which remains unaffected.

Impact

A remote attacker may obtain sensitive data.

Workaround

A workaround is not currently known for this issue. All users are advised to upgrade to the latest version of the affected package.

Resolution

All util-linux users should upgrade to version 2.12 or later:
Code:
# emerge sync
# emerge -pv ">=sys-apps/util-linux-2.12"
# emerge ">=sys-apps/util-linux-2.12"


References

CAN-2004-0080


Last edited by GLSA on Sun May 07, 2006 4:50 pm; edited 1 time in total
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum