Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

UnixWare CDE DTLogin Log Directory Insecure Permissions Vulnerability

dtlogin is a utility that allows users to log into a CDE session
either locally or remotely. dtlogin logs errors to /var/dt/Xerrors.

UnixWare 7.1 installs the CDE error log directory (/var/dt/) and its contents with 777 privileges. This makes it prone to symbolic link attacks, which may under some circumstances cause other files to be overwritten with attacker-supplied data.

This also has a potential to cause a denial of service or a loss of critical data. There also exists a possibility that a local attacker may gain elevated privileges as a result of this issue.

This issue has been confirmed for Unixware 7.1, it is not known whether other versions or distributions are affected by this issue.







 

Privacy Statement
Copyright 2008, SecurityFocus