Updated fam packages that fix an information disclosure bug are now available.
FAM, the File Alteration Monitor, provides a daemon and an API which applications can use for notification of changes in specific files or directories. A bug has been found in the way FAM handles group permissions. It is possible that a local unprivileged user can use a flaw in FAM's group handling to discover the names of files which are only viewable to users in the 'root' group. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2002-0875 to this issue. This issue only affects the version of FAM shipped with CentOS Linux 2.1. Users of FAM should update to these updated packages which contain backported patches and are not vulnerable to this issue.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center