CVE-2000-0378

The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:linux:6.1:*:*:*:*:*:*:*
cpe:2.3:o:redhat:linux:6.2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:32

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2000-05/0023.html - () http://archives.neohapsis.com/archives/bugtraq/2000-05/0023.html -
References () http://www.securityfocus.com/bid/1176 - () http://www.securityfocus.com/bid/1176 -

Information

Published : 2000-05-03 04:00

Updated : 2024-11-20 23:32


NVD link : CVE-2000-0378

Mitre link : CVE-2000-0378

CVE.ORG link : CVE-2000-0378


JSON object : View

Products Affected

redhat

  • linux