NASLDB: RHSA-2003-058: shadow-utils
General
ID: 12366
Name: RHSA-2003-058: shadow-utils
Summary: Check for the version of the shadow-utils packages
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:N
CVSS Base Vector: –
CVSS Temporal Vector: –
Port: 0
Family: Red Hat Local Security Checks
Type: Local
Description
Updated shadow-utils packages are now available. These updated packages
correct a bug that caused the useradd tool to create mail spools with
incorrect permissions.
The shadow-utils package includes programs for converting UNIX password
files to the shadow password format, plus programs for managing user and
group accounts. One of these programs is useradd, which is used to create
or update new user information.
When creating a user account, the version of useradd included in Red Hat
packages creates a mail spool file with incorrectly-set group ownership.
Instead of setting the file\‘s group ownership to the "mail" group, it is
set to the user\‘s primary group.
On systems where other users share the same primary group, this would allow
those users to be able to read and write other user mailboxes.
These errata packages contain an updated patch to useradd. Where a mail
group exists, mailboxes will be created with group mail having read and
write permissions. Otherwise the mailbox will be created without group
read and write permissions.
All users are advised to upgrade to these updated packages and also to
check the /var/spool/mail directory to ensure that mailboxes have correct
permissions.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2002-1509
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2004/07/06
Plugin
Version: 1.11
Filename: redhat-RHSA-2003-058.nasl
Filesize: 2996 bytes
MD5 Hash: 9b47f72a6bc5f3ef2eeb1146452241f4
Identification: Host/RedHat/rpm-list
Require Keys: Host/RedHat/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2004-2011 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













