MGASA-2015-0352
Dashboard / Vulnerabilities / MGASA-2015-0352
Summary: Updated util-linux packages fix CVE-2015-5224
Details: Updated util-linux packages fix security vulnerability: The chfn and chsh commands in util-linux's login-utils are vulnerable to a file name collision due to incorrect mkstemp usage. If the chfn and chsh binaries are both setuid-root they eventually call mkostemp in such a way that an attacker could repeatedly call them and eventually be able to overwrite certain files in /etc (CVE-2015-5224).
References: https://advisories.mageia.org/MGASA-2015-0352.html, https://bugs.mageia.org/show_bug.cgi?id=16641, http://openwall.com/lists/oss-security/2015/08/24/3
Affected packages
Package
Name: util-linux
Purl: pkg:rpm/mageia/util-linux?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
