A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://git.zx2c4.com/calibre-mount-helper-exploit/about/ | third party advisory exploit |
https://www.openwall.com/lists/oss-security/2011/11/02/2 | third party advisory mailing list |
https://bugs.launchpad.net/calibre/+bug/885027 | issue tracking exploit third party advisory |
https://lwn.net/Articles/464824/ | third party advisory not applicable |