chkstat in SuSE Linux 9.0 through 10.0 allows local users to modify permissions of files by creating a hardlink to a file from a world-writable directory, which can cause the link count to drop to 1 when the file is deleted or replaced, which is then modified by chkstat to use weaker permissions.
Link | Tags |
---|---|
http://www.osvdb.org/20263 | vdb entry |
http://secunia.com/advisories/17290/ | third party advisory |
http://www.novell.com/linux/security/advisories/2005_62_permissions.html | vendor advisory |
http://www.securityfocus.com/bid/15182 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/22853 | vdb entry |