systemd Session Logout File Deletion Weakness

by Carol~ Moderator - 3/19/12 7:20 AM

In Reply to: VULNERABILITIES / FIXES - March 19, 2012 by Carol~ Moderator

Release Date : 2012-03-19

Criticality level : Not critical
Impact : Manipulation of data
Where : Local system
Solution Status : Unpatched

Software: systemd

Description:
A weakness has been reported in systemd, which can be exploited by malicious, local users to manipulate certain data.

The weakness is caused due to a race condition in the systemd-logind component when removing certain records during user's logout and can be exploited to delete an arbitrary file via a symlink.

The weakness is reported in version 44 and prior.

Solution:
Fixed in the GIT repository.

Provided and/or discovered by:
Reported by Michal Schmidt, Red Hat

Original Advisory:
http://seclists.org/oss-sec/2012/q1/672

http://secunia.com/advisories/48331/