search for: unprivil

Displaying 2 results from an estimated 2 matches for "unprivil".

Did you mean: unprivi
2006 Mar 22
0
FreeBSD Security Advisory FreeBSD-SA-06:12.opie
...sed to set up OPIE authentication for a user. OPIE is enabled by default on FreeBSD through PAM. II. Problem Description The opiepasswd(1) program uses getlogin(2) to identify the user calling opiepasswd(1). In some circumstances getlogin(2) will return "root" even when running as an unprivileged user. This causes opiepasswd(1) to allow an unpriviled user to configure OPIE authentication for the root user. III. Impact In certain cases an attacker able to run commands as a non privileged users which have not explicitly logged in, for example CGI scripts run by a web server, is able to...
2006 Mar 22
0
FreeBSD Security Advisory FreeBSD-SA-06:12.opie
...sed to set up OPIE authentication for a user. OPIE is enabled by default on FreeBSD through PAM. II. Problem Description The opiepasswd(1) program uses getlogin(2) to identify the user calling opiepasswd(1). In some circumstances getlogin(2) will return "root" even when running as an unprivileged user. This causes opiepasswd(1) to allow an unpriviled user to configure OPIE authentication for the root user. III. Impact In certain cases an attacker able to run commands as a non privileged users which have not explicitly logged in, for example CGI scripts run by a web server, is able to...