Advisories:rPSA-2006-0106
From rPath Wiki
rPath Security Advisory 2006-0106-1
Published: 2006-06-15
Products
- rPath Linux 1
Rating
- Major
Exposure Level Classification
- Local Root Deterministic Information Exposure
Updated Versions
- kdebase=conary.rpath.com@rpl:1/3.4.2-3.11-1
rPath Issue Tracking System
References
Description
- KDM allows the user to select the session type for login. This setting
- is stored in the user home directory. Previous versions of KDM will
- follow a symbolic link and can thus disclose the contents of any file
- on the system (such as /etc/shadow) to arbitrary users. KDM is not the
- default window manager on rPath Linux.
Copyright 2006 rPath, Inc. This file is distributed under the terms of the MIT License. A copy is available at http://www.rpath.com/permanent/mit-license.html
