Severity: critical
Package: systemd
Tags: security

Restarting emergency.service (as done by needsrestart) within the emergency.service leads to a prompt for the root password to enter maintenance, but neither entering a valid password nor pressing ctrl+d results into a login shell.

Even worse, pressing enter shows the prompt from the former shell and I'm able to get 'bash ... command not found errors' by entering various combinations of letters and hitting return often enough. So while the shell seems to be locked, it is actually possible to run commands within the shell behind the login.


--
Mit freundlichen Grüßen


Bernd Zeimetz
Systems Engineer
Debian Developer

conova communications GmbH
Web    | http://www.conova.com/
E-Mail | b.zeim...@conova.com

Zentrale Salzburg
Karolingerstraße 36A
5020 Salzburg

Tel | +43 (0) 662 22 00 - 313
Fax | +43 (0) 662 22 00 - 209

Es gelten die Allgemeinen Geschäftsbedingungen der
conova communications GmbH, http://www.conova.com/de/agb/

Attachment: smime.p7s
Description: S/MIME cryptographic signature

Reply via email to