LWN.net Logo

pinentry: local privilege escalation

Package(s):pinentry CVE #(s):
Created:January 3, 2006 Updated:January 4, 2006
Description: Tavis Ormandy of the Gentoo Linux Security Audit Team has discovered that the pinentry ebuild incorrectly sets the permissions of the pinentry binaries upon installation, so that the sgid bit is set making them execute with the privileges of group ID 0.
Alerts:
Gentoo 200601-01 2006-01-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds