CVE-2008-0884
published 2008-04-04CVE-2008-0884: The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0.65-2 in Red Hat…
PriorityP417medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.36%
28.4th percentile
The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0.65-2 in Red Hat Enterprise Linux (RHEL) 5 uses lstat instead of stat to determine the /etc/pam.d/system-auth file permissions, leading to a change to world-writable permissions for the /etc/pam.d/system-auth-ac file, which allows local users to gain privileges by modifying this file.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
system-auth-ac is world-writable
vendor_redhat·2008-04-01·CVSS 6.9
CVE-2008-0884 [MEDIUM] CWE-732 system-auth-ac is world-writable
system-auth-ac is world-writable
The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0.65-2 in Red Hat Enterprise Linux (RHEL) 5 uses lstat instead of stat to determine the /etc/pam.d/system-auth file permissions, leading to a change to world-writable permissions for the /etc/pam.d/system-auth-ac file, which allows local users to gain privileges by modifying this file.
GHSA
GHSA-ph72-92xv-q7vm: The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0
ghsa_unreviewed·2022-05-01
CVE-2008-0884 [MEDIUM] CWE-732 GHSA-ph72-92xv-q7vm: The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0
The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0.65-2 in Red Hat Enterprise Linux (RHEL) 5 uses lstat instead of stat to determine the /etc/pam.d/system-auth file permissions, leading to a change to world-writable permissions for the /etc/pam.d/system-auth-ac file, which allows local users to gain privileges by modifying this file.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2008-0193.htmlhttp://secunia.com/advisories/29642http://securitytracker.com/id?1019740http://www.securityfocus.com/bid/28557https://bugzilla.redhat.com/show_bug.cgi?id=435442https://exchange.xforce.ibmcloud.com/vulnerabilities/41584http://rhn.redhat.com/errata/RHSA-2008-0193.htmlhttp://secunia.com/advisories/29642http://securitytracker.com/id?1019740http://www.securityfocus.com/bid/28557https://bugzilla.redhat.com/show_bug.cgi?id=435442https://exchange.xforce.ibmcloud.com/vulnerabilities/41584
2008-04-04
Published