PT-2012-1499 · Gypsy · Gypsy
Kees Cook
·
Published
2012-08-13
·
Updated
2013-12-13
·
CVE-2011-0523
CVSS v2.0
1.9
Low
| Vector | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
gypsy version 0.8
Description
The issue allows local users to read otherwise restricted files due to improper restriction of files that can be read while running with root privileges.
Recommendations
For version 0.8, restrict the use of gypsy when running with root privileges to minimize the risk of exploitation. Consider implementing additional access controls to limit the files that can be read by gypsy. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gypsy