|
|
| |
|
| |
pinentry: local privilege escalation
| Package(s): | pinentry |
CVE #(s): | |
| Created: | January 3, 2006 |
Updated: | January 4, 2006 |
| Description: |
Tavis Ormandy of the Gentoo Linux Security Audit Team has discovered
that the pinentry ebuild incorrectly sets the permissions of the
pinentry binaries upon installation, so that the sgid bit is set making
them execute with the privileges of group ID 0. |
| Alerts: |
|
( Log in to post comments)
|
|
|