CVE-2008-5394

Publication date 9 December 2008

Last updated 24 July 2024


Ubuntu priority

/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.

Status

Package Ubuntu Release Status
shadow 8.10 intrepid
Fixed 1:4.1.1-1ubuntu1.2
8.04 LTS hardy
Fixed 1:4.0.18.2-1ubuntu2.2
7.10 gutsy
Fixed 1:4.0.18.1-9ubuntu0.2
6.06 LTS dapper
Fixed 1:4.0.13-7ubuntu3.4

References

Related Ubuntu Security Notices (USN)

    • USN-695-1
    • shadow vulnerability
    • 18 December 2008

Other references