[<prev] [next>] [day] [month] [year] [list]
Message-ID: <431F2340.2080304@suresec.org>
Date: Wed, 07 Sep 2005 19:28:32 +0200
From: Suresec Advisories <advisories@...esec.org>
To: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: [ Suresec Advisories ] - Kcheckpass file creation
vulnerability
Suresec Security Advisory - #00006
05/09/05
Kcheckpass file creation vulnerability
Advisory: http://www.suresec.org/advisories/adv6.pdf
Description:
A lockfile handling error was found in kcheckpass which can,
in certain configurations be used to create world writable files.
Exploitation of this vulnerability may lead to elevated privileges .
The vulnerability was discovered by Ilja van Sprundel.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists