systemd Session Logout File Deletion Weakness
by Carol~
- 3/19/12 7:20 AM
In Reply to: VULNERABILITIES / FIXES - March 19, 2012 by Carol~
Release Date : 2012-03-19
Criticality level : Not critical
Impact : Manipulation of data
Where : Local system
Solution Status : Unpatched
Software: systemd
Description:
A weakness has been reported in systemd, which can be exploited by malicious, local users to manipulate certain data.
The weakness is caused due to a race condition in the systemd-logind component when removing certain records during user's logout and can be exploited to delete an arbitrary file via a symlink.
The weakness is reported in version 44 and prior.
Solution:
Fixed in the GIT repository.
Provided and/or discovered by:
Reported by Michal Schmidt, Red Hat
Original Advisory:
http://seclists.org/oss-sec/2012/q1/672
http://secunia.com/advisories/48331/

Moderator
CNET Staff
Samsung Staff
Dell Staff