Bug 233589
Summary: | inserting a letter in "UID Number" fileld gives user a root privileges | ||
---|---|---|---|
Product: | [Retired] 389 | Reporter: | Robert Ludvik <r> |
Component: | Admin | Assignee: | Rich Megginson <rmeggins> |
Status: | CLOSED NOTABUG | QA Contact: | Orla Hegarty <ohegarty> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 1.0.4 | ||
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2007-03-23 14:55:05 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Robert Ludvik
2007-03-23 11:41:24 UTC
I think this is an operating system thing - pam_ldap and/or nss_ldap should refuse to use an invalid uid number. That is, in this case, FDS is merely the storage for the uid value - it doesn't actually do any enforcement, it just gives that value back to pam/nss. What happens if you edit /etc/passwd and put a textual uid number in the uid number field? > What happens if you edit /etc/passwd and put a textual uid number in the uid
>number field?
If i change my /etc/passwd from:
r:x:501:502::/home/r:/bin/bash
into:
r:x:abc:502::/home/r:/bin/bash
it says: "Login incorrect" and I can't login.
Then it must be a bug in pam_ldap or nss_ldap - they should cause the same error. |