Secunia Advisory SA19331Debian Network Installation Insecure Default Directory Permissions
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Ferenczi Viktor has discovered a weakness in Debian, which can be exploited by malicious, local users to bypass certain security restrictions and potentially cause a DoS (Denial of Service). The weakness is caused due to the "/var/log/debian-installer/cdebconf" directory being left behind with world-writable permissions after completion of installation using the network install CD. This can potentially be exploited by malicious users to cause a DoS by e.g. filling up the /var/log partition. The vulnerability has been confirmed in debian-31r1a-i386-netinst.iso and also reported in version 3.1r1. Other versions may also be affected. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
166 views | ![]() |
| Limny Multiple Vulnerabilities | |
249 views | ![]() |
| Ubuntu update for thunderbird | |
184 views | ![]() |
| Debian update for php5 | |