Title : util-linux-ng "logaudit()" Audit Logs Injection Security Weakness VUPEN ID : VUPEN/ADV-2008-1392 CVE ID : CVE-2008-1926
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-30
Technical Description
A security weakness has been identified in util-linux-ng, which could be exploited by attackers to bypass security checks. This issue is caused by an error in the "logaudit()" [login-utils/login.c] function when logging user-supplied login names, which could be exploited by attackers to hide certain activities and modify portions of log events by injecting arbitrary addresses to the audit log.
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.