The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local users of the workstation console to gain privileges and change the network configuration.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/42867 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=448557 | |
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00974.html | vendor advisory |
http://secunia.com/advisories/30399 | third party advisory vendor advisory |