Advisories Blog | G5 Cyber Security

Debian Linux Security Advisory 1709-1

Debian Security Advisory 1709-1 – Paul Szabo discovered that login, the system login tool, did not correctly handle symlinks while setting up tty permissions. If a local attacker were able to gain control of the system utmp file, they could cause login to change the ownership and permissions on arbitrary files, leading to a root privilege escalation.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74185/dsa-1709-1.txt

Source: https://packetstormsecurity.com/files/74185/Debian-Linux-Security-Advisory-1709-1.html

Exit mobile version