PT-2008-2501 · Ibm+1 · Lspp-Eal4-Config-Ibm+2
Mark J. Cox
·
Published
2008-04-04
·
Updated
2023-02-13
·
CVE-2008-0884
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
capp-lspp-eal4-config-hp versions prior to 0.65-2
capp-lspp-config in lspp-eal4-config-ibm versions prior to 0.65-2
Description
The issue arises from the Replace function in the capp-lspp-config script, which uses
lstat instead of stat to determine file permissions. This leads to a change in permissions for the /etc/pam.d/system-auth-ac file, making it world-writable. As a result, local users can modify this file to gain privileges.Recommendations
For capp-lspp-eal4-config-hp versions prior to 0.65-2, update to version 0.65-2 or later.
For capp-lspp-config in lspp-eal4-config-ibm versions prior to 0.65-2, update to version 0.65-2 or later.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Capp-Lspp-Config
Capp-Lspp-Eal4-Config-Hp
Lspp-Eal4-Config-Ibm