PT-2008-3408 · Tss · Tss

Steve Kemp

·

Published

2008-04-17

·

Updated

2017-08-08

·

CVE-2008-1877

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions tss version 0.8.1
Description The issue allows local users to read arbitrary files. This is achieved via the -a parameter, which is processed while tss is running with privileges.
Recommendations For version 0.8.1, avoid using the -a parameter until a fix is available. As a temporary workaround, consider restricting the privileges under which tss runs to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1877

Affected Products

Tss