Bug 1274 - 'su' reads pwd from stdin
Summary: 'su' reads pwd from stdin
Alias: None
Product: Red Hat Linux
Classification: Retired
Component: sh-utils   
(Show other bugs)
Version: 5.2
Hardware: i386 Linux
Target Milestone: ---
Assignee: Cristian Gafton
QA Contact:
Keywords: Security
Depends On:
TreeView+ depends on / blocked
Reported: 1999-02-22 08:10 UTC by borgia
Modified: 2008-05-01 15:37 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 1999-03-31 20:51:21 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

Description borgia 1999-02-22 08:10:01 UTC
The fact that 'su' reads the password from stdin allows any
user to fake a login prompt and collect other users'
passwords. I've not been able to get a shell out of this
bug, but execution of commands as another user is indeed
Solution: compile 'su' so that it does not read the password
from stdin (as other dists do)

Comment 1 Jay Turner 1999-03-26 20:09:59 UTC
Erik please verify if this is incorrect, and please close it if so.

Comment 2 Jay Turner 1999-03-26 20:36:59 UTC
Christian, look at this and verify that is incorrect, if so then
please close it.

Comment 3 Erik Troan 1999-03-31 20:51:59 UTC
fixed in sh-utils-1.16-18

Note You need to log in before you can comment on or make changes to this bug.