gypsy 0.8 does not properly restrict the files that can be read while running with root privileges, which allows local users to read otherwise restricted files via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2011/01/25/10 | mailing list |
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107020.html | vendor advisory |
http://lists.opensuse.org/opensuse-updates/2012-07/msg00034.html | vendor advisory |
https://bugs.freedesktop.org/show_bug.cgi?id=33431 | |
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106919.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106927.html | vendor advisory |
http://www.openwall.com/lists/oss-security/2011/01/24/10 | mailing list |
http://secunia.com/advisories/49991 | third party advisory vendor advisory |
https://bugs.launchpad.net/ubuntu/+source/gypsy/+bug/690323 | |
http://cgit.freedesktop.org/gypsy/commit/?id=40101707cddb319481133b2a137294b6b669bd16 | patch exploit |