PT-2010-1147 · Gnustep · Gnustep-Base

Dan Rosenberg

+1

·

Publicado

2010-05-12

·

Atualizado

2014-01-20

·

CVE-2010-1457

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions gnustep-base versions prior to 1.20.1
Description The issue concerns multiple vulnerabilities in the gnustep-base package that can lead to breaches in confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally. Specifically, a flaw in Tools/gdomap.c in gdomap in GNUstep Base before version 1.20.0 allows local users to read arbitrary files via certain options, which prints file contents in an error message.
Recommendations For versions prior to 1.20.1, update to version 1.20.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the gdomap tool until a patch is available.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09691
CVE-2010-1457

Produtos afetados

Gnustep-Base