[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ Suresec Advisories ] - Kcheckpass file creation vulnerability
- To: full-disclosure@xxxxxxxxxxxxxxxxx, bugtraq@xxxxxxxxxxxxxxxxx
- Subject: [ Suresec Advisories ] - Kcheckpass file creation vulnerability
- From: Suresec Advisories <advisories@xxxxxxxxxxx>
- Date: Wed, 07 Sep 2005 19:28:32 +0200
Suresec Security Advisory - #00006
05/09/05
Kcheckpass file creation vulnerability
Advisory: http://www.suresec.org/advisories/adv6.pdf
Description:
A lockfile handling error was found in kcheckpass which can,
in certain configurations be used to create world writable files.
Exploitation of this vulnerability may lead to elevated privileges .
The vulnerability was discovered by Ilja van Sprundel.