|
|
| |
|
| |
rmake: privilege escalation
| Package(s): | rmake |
CVE #(s): | CVE-2007-0536
CVE-2007-0557
|
| Created: | January 26, 2007 |
Updated: | January 31, 2007 |
| Description: |
Rmake prior to version 1.0.3-2-0.1 does not drop supplemental users in the
changeroot environment for builds. This provides malicious packages with
excess permissions that are configuration-dependent, and may allow local
users to run arbitrary code as the root user. |
| Alerts: |
|
( Log in to post comments)
|
|
|