eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/6914 | vdb entry patch |
http://archives.neohapsis.com/archives/bugtraq/2003-02/0278.html | mailing list exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11380 | vdb entry |