|
UnixWare CDE DTLogin Log Directory Insecure Permissions Vulnerability
dtlogin is a utility that allows users to log into a CDE session either locally or remotely. dtlogin logs errors to /var/dt/Xerrors. UnixWare 7.1 installs the CDE error log directory (/var/dt/) and its contents with 777 privileges. This makes it prone to symbolic link attacks, which may under some circumstances cause other files to be overwritten with attacker-supplied data. This also has a potential to cause a denial of service or a loss of critical data. There also exists a possibility that a local attacker may gain elevated privileges as a result of this issue. This issue has been confirmed for Unixware 7.1, it is not known whether other versions or distributions are affected by this issue. |
|
|
Privacy Statement |