Advisories ยป MGASA-2015-0352

Updated util-linux packages fix CVE-2015-5224

Publication date: 08 Sep 2015
Type: security
Affected Mageia releases : 5
CVE: CVE-2015-5224

Description

Updated util-linux packages fix security vulnerability:

The chfn and chsh commands in util-linux's login-utils are vulnerable to a
file name collision due to incorrect mkstemp usage. If the chfn and chsh
binaries are both setuid-root they eventually call mkostemp in such a way that
an attacker could repeatedly call them and eventually be able to overwrite
certain files in /etc (CVE-2015-5224).
                

References

SRPMS

5/core