userOsa can overwrite passwd and shadow

© December 2004

In article <7tvq0m$gu1$1@hendrix.postino.com>,
Danny Aldham <danny@hendrix.postino.com> wrote:
>Any user may overwrite any file with group auth (i.e. /etc/shadow,
>/etc/passwd) using /etc/sysadm.d/bin/userOsa.

My quick fix for this is to edit userOsa and replace the string
"debug.log" with "/dev/null".
John W. Temples, III

This is a Unix/Linux resource website. It contains technical articles about Unix, Linux and general computing related subjects, opinion, news, help files, how-to's, tutorials and more.

