First published: Mon May 02 2005(Updated: )
The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mandrakesoft Mandrake Lam-runtime | =7.0.6.2mdk |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1379 is considered a high-severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2005-1379, ensure that the mpi user created by the lam-runtime package is secured with a password or remove the mpi user if it is not required.
Users of the Mandrake Linux version with the lam-runtime package version 7.0.6-2mdk are affected by CVE-2005-1379.
CVE-2005-1379 can be exploited by local users to gain elevated privileges on the system.
You should check for security updates or patches from Mandrake Linux that address CVE-2005-1379.