[36012] in bugtraq

home help back first fref pref prev next nref lref last post

SuSE Linux K-Menu YAST Control Center Priviledge Escalation

daemon@ATHENA.MIT.EDU (Jordan Pilat)
Fri Aug 6 20:55:25 2004

Date: 6 Aug 2004 02:45:45 -0000
Message-ID: <20040806024545.14094.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Jordan Pilat <cacophony@syncreate.org>
To: bugtraq@securityfocus.com



A vulnerability exists in the implementation of 
placing the SuSE YAST Control Center in the K Menu.  
Normally, one would be required to authenticate as 
root before being granted access to the YAST Control 
Center.  When placing the 'preferences' submenu in 
the K Menu (in the 'submenu' section under the 
'Menus' tab of the K menu panel preferences), 
however, one can not only access, but make changes to 
the options in the YAST control center without having 
to authenticate as root. 

home help back first fref pref prev next nref lref last post