SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
http://securitytracker.com/id?1014153 | vdb entry third party advisory broken link |
http://bugs.gentoo.org/show_bug.cgi?id=93558 | issue tracking |
http://www.gentoo.org/security/en/glsa/glsa-200506-05.xml | third party advisory vendor advisory |
http://secunia.com/advisories/15632 | third party advisory broken link |