g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive data.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://github.com/MatMoul/g810-led/pull/297 | third party advisory patch |
https://bugs.debian.org/1024998 | third party advisory issue tracking |
https://lists.debian.org/debian-lts-announce/2022/12/msg00002.html | third party advisory mailing list |