A certain Ubuntu build procedure for perf, as distributed in the Linux kernel packages in Ubuntu 10.04 LTS, 12.04 LTS, 12.10, 13.04, and 13.10, sets the HOME environment variable to the ~buildd directory and consequently reads the system configuration file from the ~buildd directory, which allows local users to gain privileges by leveraging control over the buildd account.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.ubuntu.com/usn/USN-1943-1 | vendor advisory |
http://www.ubuntu.com/usn/USN-1938-1 | vendor advisory |
http://www.ubuntu.com/usn/USN-1944-1 | vendor advisory |
http://www.ubuntu.com/usn/USN-1945-1 | vendor advisory |
https://launchpad.net/bugs/1206200 | |
https://lists.ubuntu.com/archives/kernel-team/2013-July/031248.html | mailing list |
http://www.ubuntu.com/usn/USN-1939-1 | vendor advisory |
https://lists.ubuntu.com/archives/kernel-team/2013-July/031249.html | mailing list |
http://www.ubuntu.com/usn/USN-1947-1 | vendor advisory |
http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-1060.html | vendor advisory |
http://www.ubuntu.com/usn/USN-1941-1 | vendor advisory |
http://www.ubuntu.com/usn/USN-1942-1 | vendor advisory |
http://www.ubuntu.com/usn/USN-1946-1 | vendor advisory |