PT-2007-6677 · Rpath+1 · Rpath Linux+1
Published
2007-10-28
·
Updated
2018-10-15
·
CVE-2007-5686
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
rPath Linux 1
Description
The issue allows local users to obtain sensitive information regarding authentication attempts due to insecure permissions set for the /var/log/btmp file. This also prevents sshd from logging failed authentication attempts by remote attackers because sshd detects the insecure permissions and does not log certain events.
Recommendations
For rPath Linux 1, consider changing the permissions of the /var/log/btmp file to secure it and ensure that sshd can log failed authentication attempts properly. As a temporary workaround, monitor the system for potential security breaches, focusing on authentication attempts.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Rpath Linux