Description
Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.
Affected products
- mandrakesoft / mandrake_linux6.0 – 6.0
- mandrakesoft / mandrake_linux6.1 – 6.1
- RedHat / linux6.0 – 6.0
- RedHat / linux6.1 – 6.1
- turbolinux / turbolinux3.5b2 – 3.5b2
- turbolinux / turbolinux4.2 – 4.2
- turbolinux / turbolinux4.4 – 4.4
- turbolinux / turbolinux6.0.2 – 6.0.2