Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-3249

Опубликовано: 05 нояб. 2018
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2018-3249: setup security and bug fix update (LOW)

[2.8.71-10]

  • fix crudp name in /etc/protocols (#1566469)
  • do not list /sbin/nologin and /usr/sbin/nologin in /etc/shells (#1571104)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

setup

2.8.71-10.el7

Oracle Linux x86_64

setup

2.8.71-10.el7

Связанные CVE

Связанные уязвимости

CVSS3: 4.8
redhat
больше 7 лет назад

setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates security assumptions made by pam_shells and some daemons which allow access based on a user's shell being listed in /etc/shells. Under some circumstances, users which had their shell changed to /sbin/nologin could still access the system.

CVSS3: 4.8
nvd
больше 7 лет назад

setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates security assumptions made by pam_shells and some daemons which allow access based on a user's shell being listed in /etc/shells. Under some circumstances, users which had their shell changed to /sbin/nologin could still access the system.

CVSS3: 5.3
github
больше 3 лет назад

setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates security assumptions made by pam_shells and some daemons which allow access based on a user's shell being listed in /etc/shells. Under some circumstances, users which had their shell changed to /sbin/nologin could still access the system.

CVSS3: 4.8
fstec
больше 7 лет назад

Уязвимость модуля pam_shells пакета файлов конфигурации и настройки системы Setup операционных систем Red Hat Enterprise Linux и Fedora, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации