Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

util-linux-ng 'login' Remote Log Injection Weakness

The 'login' utility from 'util-linux-ng' is prone to a weakness that allows remote attackers to inject false information into log files. This issue occurs because the utility fails to properly sanitize user-supplied input.

Successful exploits allow malicious users to inject false information into log files. The injected information may aid in indirect attacks against log-monitoring systems or may allow attackers to obfuscate malicious activity.

Versions prior to util-linux-ng 2.13.1.1 are prone to this issue.







 

Privacy Statement
Copyright 2009, SecurityFocus