LWN.net Logo

glib2.0: privilege escalation

Package(s):glib2.0 CVE #(s):CVE-2009-3289
Created:September 24, 2009 Updated:April 27, 2010
Description: From the Mandriva alert: The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
Alerts:
SuSE SUSE-SR:2010:010 2010-04-27
Mandriva MDVSA-2009:245 2009-09-24
Ubuntu USN-841-1 2009-10-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds