CVE-2008-5394
published 2008-12-09CVE-2008-5394: /bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files…
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
0.95%
57.3th percentile
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | shadow | < shadow 1:4.1.1-6 (bookworm) | shadow 1:4.1.1-6 (bookworm) |
| debian | shadow | — | — |
| shadow_project | shadow | >= 0 < 1:4.1.1-6 | 1:4.1.1-6 |
| shadow_project | shadow | >= 0 < 1:4.1.1-6 | 1:4.1.1-6 |
| shadow_project | shadow | >= 0 < 1:4.1.1-6 | 1:4.1.1-6 |
| shadow_project | shadow | >= 0 < 1:4.1.1-6 | 1:4.1.1-6 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
shadow vulnerability
vendor_ubuntu·2008-12-18
CVE-2008-5394 shadow vulnerability
Title: shadow vulnerability
Summary: shadow vulnerability
Paul Szabo discovered a race condition in login. While setting up
tty permissions, login did not correctly handle symlinks. If a local
attacker were able to gain control of the system utmp file, they could
cause login to change the ownership and permissions on arbitrary files,
leading to a root privilege escalation.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2008-5394: shadow - /bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux dist...
vendor_debian·2008·CVSS 7.2
CVE-2008-5394 [HIGH] CVE-2008-5394: shadow - /bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux dist...
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.
Scope: local
bookworm: resolved (fixed in 1:4.1.1-6)
bullseye: resolved (fixed in 1:4.1.1-6)
forky: resolved (fixed in 1:4.1.1-6)
sid: resolved (fixed in 1:4.1.1-6)
trixie: resolved (fixed in 1:4.1.1-6)
Red Hat
CVE-2008-5394: /bin/login in shadow 4
vendor_redhat·CVSS 7.2
CVE-2008-5394 [HIGH] CVE-2008-5394: /bin/login in shadow 4
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.
Statement: Not vulnerable. This issue did not affect the versions of the util-linux packages (providing /bin/login), as shipped with Red Hat Enterprise Linux 2.1, 3, 4 or 5.
GHSA
GHSA-5848-87gf-wvqv: /bin/login in shadow 4
ghsa_unreviewed·2022-05-14
CVE-2008-5394 [HIGH] CWE-59 GHSA-5848-87gf-wvqv: /bin/login in shadow 4
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.
OSV
CVE-2008-5394: /bin/login in shadow 4
osv·2008-12-09·CVSS 7.2
CVE-2008-5394 [HIGH] CVE-2008-5394: /bin/login in shadow 4
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.
No detection rules found.
No writeups or analysis indexed.
http://bugs.debian.org/332198http://bugs.debian.org/505071http://bugs.debian.org/505271http://osvdb.org/52200http://security.gentoo.org/glsa/glsa-200903-24.xmlhttp://securityreason.com/securityalert/4695http://www.mandriva.com/security/advisories?name=MDVSA-2009:062http://www.securityfocus.com/archive/1/498769/100/0/threadedhttp://www.securityfocus.com/bid/32552http://www.ubuntu.com/usn/usn-695-1https://exchange.xforce.ibmcloud.com/vulnerabilities/47037https://www.exploit-db.com/exploits/7313http://bugs.debian.org/332198http://bugs.debian.org/505071http://bugs.debian.org/505271http://osvdb.org/52200http://security.gentoo.org/glsa/glsa-200903-24.xmlhttp://securityreason.com/securityalert/4695http://www.mandriva.com/security/advisories?name=MDVSA-2009:062http://www.securityfocus.com/archive/1/498769/100/0/threadedhttp://www.securityfocus.com/bid/32552http://www.ubuntu.com/usn/usn-695-1https://exchange.xforce.ibmcloud.com/vulnerabilities/47037https://www.exploit-db.com/exploits/7313
2008-12-09
Published