liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013.
Link | Tags |
---|---|
http://www.novell.com/linux/security/advisories/2005_22_sr.html | patch vendor advisory |
http://www.securityfocus.com/bid/15026 | vdb entry patch |