PT-2012-1499 · Gypsy · Gypsy
Kees Cook
·
Publicado
2012-08-13
·
Atualizado
2013-12-13
·
CVE-2011-0523
CVSS v2.0
1.9
Baixa
| Vetor | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
gypsy version 0.8
Description
The issue allows local users to read otherwise restricted files due to improper restriction of files that can be read while running with root privileges.
Recommendations
For version 0.8, restrict the use of gypsy when running with root privileges to minimize the risk of exploitation. Consider implementing additional access controls to limit the files that can be read by gypsy. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gypsy