|Category:||Mageia Linux Local Security Checks|
|Title:||Mageia Linux Local Check: mgasa-2015-0352|
|Summary:||Mageia Linux Local Security Checks mgasa-2015-0352|
Mageia Linux Local Security Checks mgasa-2015-0352
Updated util-linux packages fix security vulnerability: The chfn and chsh commands in util-linux's login-utils are vulnerable to a file name collision due to incorrect mkstemp usage. If the chfn and chsh binaries are both setuid-root they eventually call mkostemp in such a way that an attacker could repeatedly call them and eventually be able to overwrite certain files in /etc (CVE-2015-5224).
Update the affected packages to the latest available version.
Common Vulnerability Exposure (CVE) ID: CVE-2015-5224|
BugTraq ID: 76467
|Copyright||Copyright (C) 2015 Eero Volotinen|
|This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.