userOsa can overwrite passwd and shadow

Newsgroups: comp.unix.sco.misc
Subject: Re: BUGTRAQ report
From: john@kuwait.net (John Temples)
Date: Tue, 12 Oct 1999 19:16:47 GMT

In article <7tvq0m$gu1$1@hendrix.postino.com>,
Danny Aldham <danny@hendrix.postino.com> wrote:
>Any user may overwrite any file with group auth (i.e. /etc/shadow,
>/etc/passwd) using /etc/sysadm.d/bin/userOsa.

My quick fix for this is to edit userOsa and replace the string
"debug.log" with "/dev/null".
John W. Temples, III

