efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/4240 | vdb entry vendor advisory |
http://melkor.dnp.fmph.uniba.sk/~garabik/efingerd/efingerd_1.6.2.tar.gz | |
http://www.iss.net/security_center/static/8381.php | vdb entry patch vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-03/0050.html | mailing list |