sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Debian_linux |
Debian |
2.2 |
2.2 |
References