Personal tools
     DOCUMENTATION

Advisories:rPSA-2006-0106

From rPath Wiki

Jump to: navigation, search

rPath Security Advisory 2006-0106-1

Published: 2006-06-15

Products

  • rPath Linux 1

Rating

Major

Exposure Level Classification

Local Root Deterministic Information Exposure

Updated Versions

  • kdebase=conary.rpath.com@rpl:1/3.4.2-3.11-1

rPath Issue Tracking System

References

Description

KDM allows the user to select the session type for login. This setting
is stored in the user home directory. Previous versions of KDM will
follow a symbolic link and can thus disclose the contents of any file
on the system (such as /etc/shadow) to arbitrary users. KDM is not the
default window manager on rPath Linux.

Copyright 2006 rPath, Inc. This file is distributed under the terms of the MIT License. A copy is available at http://www.rpath.com/permanent/mit-license.html