Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2019/10/09/4 | mailing list third party advisory exploit |
http://www.openwall.com/lists/oss-security/2019/10/10/1 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2019/10/17/3 | third party advisory mailing list |