PT-2008-3408 · Tss · Tss
Steve Kemp
·
Published
2008-04-17
·
Updated
2017-08-08
·
CVE-2008-1877
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
tss version 0.8.1
Description
The issue allows local users to read arbitrary files. This is achieved via the
-a parameter, which is processed while tss is running with privileges.Recommendations
For version 0.8.1, avoid using the
-a parameter until a fix is available. As a temporary workaround, consider restricting the privileges under which tss runs to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tss