Secunia Advisory SA19331Debian Network Installation Insecure Default Directory Permissions
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Ferenczi Viktor has discovered a weakness in Debian, which can be exploited by malicious, local users to bypass certain security restrictions and potentially cause a DoS (Denial of Service). The weakness is caused due to the "/var/log/debian-installer/cdebconf" directory being left behind with world-writable permissions after completion of installation using the network install CD. This can potentially be exploited by malicious users to cause a DoS by e.g. filling up the /var/log partition. The vulnerability has been confirmed in debian-31r1a-i386-netinst.iso and also reported in version 3.1r1. Other versions may also be affected. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
74 views | ![]() |
Debian update for linux-2.6![]() | |
63 views | ![]() |
Debian update for moin![]() | |
122 views | ![]() |
| Ubuntu update for MoinMoin | |