PT-2009-5602 · Gnome+1 · Nautilus+1

·

CVE-2009-3289

·

Published

2009-09-22

·

Updated

2024-02-08

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions glib version 2.0
Description The issue allows user-assisted local users to modify files of other users. This is demonstrated by using Nautilus to modify the permissions of the user home directory. The g file copy function sets the permissions of a target file to the permissions of a symbolic link, which has permissions set to 777.
Recommendations For glib version 2.0, consider restricting the use of the g file copy function until a patch is available to prevent unintended permission changes. As a temporary workaround, avoid using Nautilus to modify file permissions to minimize the risk of exploitation.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3289

Affected Products

Nautilus
Glib