sash prior to 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
debian debian linux 2.2 |