PT-2009-5602 · Gnome+1 · Nautilus+1
Pedro Villavicencio
·
Published
2009-09-22
·
Updated
2024-02-08
·
CVE-2009-3289
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
glib version 2.0
Description
The issue allows user-assisted local users to modify files of other users. This is demonstrated by using Nautilus to modify the permissions of the user home directory. The
g file copy function sets the permissions of a target file to the permissions of a symbolic link, which has permissions set to 777.Recommendations
For glib version 2.0, consider restricting the use of the
g file copy function until a patch is available to prevent unintended permission changes. As a temporary workaround, avoid using Nautilus to modify file permissions to minimize the risk of exploitation.Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nautilus
Glib