vendor:
Ubuntu Linux
by:
Anonymous
7,2
CVSS
HIGH
Local root by adding temporary user toor:toor with id 0 to /etc/passwd & /etc/shadow
264
CWE
Product Name: Ubuntu Linux
Affected Version From: pam-1.1.0
Affected Version To: pam-1.1.0
Patch Exists: YES
Related CWE: CVE-2010-0832
CPE: a:ubuntu:ubuntu_linux:9.10
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 9.10 (Karmic Koala), Ubuntu 10.04 LTS (Lucid Lynx)
2010
Ubuntu PAM MOTD local root
Local root by adding temporary user toor:toor with id 0 to /etc/passwd & /etc/shadow. Does not prompt for login by creating temporary SSH key and authorized_keys entry.
Mitigation:
sudo aptitude -y update; sudo aptitude -y install libpam~n~i