CVE-2007-1716

pam_console does not properly restore ownership for certain console devices when there are multiple users logged into the console and one user logs out, which might allow local users to gain privileges.
References
Link Resource
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
http://osvdb.org/37271
http://secunia.com/advisories/25631
http://secunia.com/advisories/25894
http://secunia.com/advisories/26909
http://secunia.com/advisories/27590
http://secunia.com/advisories/27706
http://secunia.com/advisories/28319
http://security.gentoo.org/glsa/glsa-200711-23.xml
http://support.avaya.com/elmodocs2/security/ASA-2007-526.htm
http://www.redhat.com/support/errata/RHSA-2007-0465.html
http://www.redhat.com/support/errata/RHSA-2007-0555.html
http://www.redhat.com/support/errata/RHSA-2007-0737.html
http://www.vupen.com/english/advisories/2007/3229
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230823
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11483
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
http://osvdb.org/37271
http://secunia.com/advisories/25631
http://secunia.com/advisories/25894
http://secunia.com/advisories/26909
http://secunia.com/advisories/27590
http://secunia.com/advisories/27706
http://secunia.com/advisories/28319
http://security.gentoo.org/glsa/glsa-200711-23.xml
http://support.avaya.com/elmodocs2/security/ASA-2007-526.htm
http://www.redhat.com/support/errata/RHSA-2007-0465.html
http://www.redhat.com/support/errata/RHSA-2007-0555.html
http://www.redhat.com/support/errata/RHSA-2007-0737.html
http://www.vupen.com/english/advisories/2007/3229
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230823
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11483
Configurations

Configuration 1 (hide)

cpe:2.3:o:redhat:enterprise_linux:4.4:*:*:*:*:*:*:*

History

21 Nov 2024, 00:28

Type Values Removed Values Added
References () ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc - () ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc -
References () http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html -
References () http://osvdb.org/37271 - () http://osvdb.org/37271 -
References () http://secunia.com/advisories/25631 - () http://secunia.com/advisories/25631 -
References () http://secunia.com/advisories/25894 - () http://secunia.com/advisories/25894 -
References () http://secunia.com/advisories/26909 - () http://secunia.com/advisories/26909 -
References () http://secunia.com/advisories/27590 - () http://secunia.com/advisories/27590 -
References () http://secunia.com/advisories/27706 - () http://secunia.com/advisories/27706 -
References () http://secunia.com/advisories/28319 - () http://secunia.com/advisories/28319 -
References () http://security.gentoo.org/glsa/glsa-200711-23.xml - () http://security.gentoo.org/glsa/glsa-200711-23.xml -
References () http://support.avaya.com/elmodocs2/security/ASA-2007-526.htm - () http://support.avaya.com/elmodocs2/security/ASA-2007-526.htm -
References () http://www.redhat.com/support/errata/RHSA-2007-0465.html - () http://www.redhat.com/support/errata/RHSA-2007-0465.html -
References () http://www.redhat.com/support/errata/RHSA-2007-0555.html - () http://www.redhat.com/support/errata/RHSA-2007-0555.html -
References () http://www.redhat.com/support/errata/RHSA-2007-0737.html - () http://www.redhat.com/support/errata/RHSA-2007-0737.html -
References () http://www.vupen.com/english/advisories/2007/3229 - () http://www.vupen.com/english/advisories/2007/3229 -
References () https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230823 - () https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230823 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11483 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11483 -

Information

Published : 2007-03-27 22:19

Updated : 2024-11-21 00:28


NVD link : CVE-2007-1716

Mitre link : CVE-2007-1716

CVE.ORG link : CVE-2007-1716


JSON object : View

Products Affected

redhat

  • enterprise_linux