Contents

Wrong password check in sm_passd

  • Issue date: 2007/24/01

Target platform

All SEPsesam servers and remote device servers on Linux

Description

Because of a wrong password check in sm_passd someone can escape from Sesam work directory with root rights

Howto fix

  • edit <SESAM_ROOT>/var/ini/stpd.ini
  • remove root from AUTH_USERS

  • restart sm_passd with sm_main reload passd
  • This procedure must be performed on all Remote Device Servers, as well.

Request Call

Our sales team would be happy to assist you!

Download

SEP 30-day Trial

You must login or use current login to download the FREE trial.

Media Library

Browse and discover videos by SEP.