yiff server (yiff-server) 2.14.2 on Debian GNU/Linux runs as root and does not properly verify ownership of files that it opens, which allows local users to read arbitrary files.
Link | Tags |
---|---|
http://secunia.com/advisories/17242 | third party advisory vendor advisory |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=334616 | |
http://www.securityfocus.com/bid/15140 | vdb entry |
http://www.osvdb.org/20074 | vdb entry |