chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/415725/30/0/threaded | vendor advisory |
http://www.osvdb.org/20525 | vdb entry |
http://secunia.com/advisories/17469 | third party advisory |
http://www.securityfocus.com/bid/15314 | vdb entry |