Vulnerabilities > CVE-2002-1509 - Unspecified vulnerability in Redhat Linux 7.2/7.3/8.0

047910
CVSS 3.6 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
local
low complexity
redhat
nessus

Summary

A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of the new user's group (mode 660), which allows other users in the same group to read or modify the new user's incoming email.

Vulnerable Configurations

Part Description Count
OS
Redhat
4

Nessus

  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2003-026.NASL
    descriptionThe shadow-utils package contains the tool useradd, which is used to create or update new user information. When useradd creates an account, it would create it with improper permissions; instead of having it owned by the group mail, it would be owned by the user
    last seen2020-06-01
    modified2020-06-02
    plugin id14010
    published2004-07-31
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14010
    titleMandrake Linux Security Advisory : shadow-utils (MDKSA-2003:026)
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2003-058.NASL
    descriptionUpdated shadow-utils packages are now available. These updated packages correct a bug that caused the useradd tool to create mail spools with incorrect permissions. The shadow-utils package includes programs for converting UNIX password files to the shadow password format, plus programs for managing user and group accounts. One of these programs is useradd, which is used to create or update new user information. When creating a user account, the version of useradd included in Red Hat packages creates a mail spool file with incorrectly-set group ownership. Instead of setting the file
    last seen2020-06-01
    modified2020-06-02
    plugin id12366
    published2004-07-06
    reporterThis script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/12366
    titleRHEL 2.1 : shadow-utils (RHSA-2003:058)

Redhat

advisories
  • rhsa
    idRHSA-2003:057
  • rhsa
    idRHSA-2003:058