PT-2006-2328 · Dietlibc · Runit

Tino Keitel

·

Published

2006-03-20

·

Updated

2017-07-20

·

CVE-2006-1319

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions runit version 1.3.3-1
Description The issue arises from improper handling of multiple groups specified in the -u option by chpst in runit. This causes chpst to assign permissions for the root group due to inconsistent bit sizes for the gid t type when compiled on little endian i386 machines against dietlibc.
Recommendations For runit version 1.3.3-1, consider avoiding the use of multiple groups with the -u option until a fix is available. As a temporary workaround, restrict the use of the -u option to a single group to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1319

Affected Products

Runit