Caldera OpenLinux "help" Root User Vulnerability

When installing Caldera OpenLinux 2.2 using the LISA book disk an account with root privileges called "help" is created with no password. This account is not deleted from the system when installation is compleated nor is a password assigned to it. Anyone can logon into the system as "help" and obtain root privileges.

This vulnerability only affect the LISA style of installation. The new Lizard (graphical) installation interface is not affected.


 

Privacy Statement
Copyright 2010, SecurityFocus