chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id?1006035 | vdb entry |
http://www.securityfocus.com/archive/1/309962 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11233 | vdb entry |
http://securityreason.com/securityalert/3238 | third party advisory |
http://www.securityfocus.com/bid/6748 | vdb entry |
http://www.epita.fr/~bevand_m/asa/asa-0001 |