USN-695-1: shadow vulnerability
18 December 2008
shadow vulnerability
Releases
Packages
- shadow -
Details
Paul Szabo discovered a race condition in login. While setting up
tty permissions, login did not correctly handle symlinks. If a local
attacker were able to gain control of the system utmp file, they could
cause login to change the ownership and permissions on arbitrary files,
leading to a root privilege escalation.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 8.10
Ubuntu 8.04
Ubuntu 7.10
Ubuntu 6.06
In general, a standard system upgrade is sufficient to effect the
necessary changes.