|
|
| |
|
| |
python-paste-script: insecure root GID accessible files
| Package(s): | python-paste-script |
CVE #(s): | CVE-2012-0878
|
| Created: | April 9, 2012 |
Updated: | August 28, 2012 |
| Description: |
From the Red Hat bugzilla:
A security flaw was found in the way Paster, a pluggable command-line frontend,
when started as root (for example to have access to privileged port) to serve a
web based application, performed privileges dropping upon startup
(supplementary groups were not dropped properly regardless of the UID, GID
specified in the .ini configuration file or in the --user and --group CL
arguments). A remote attacker could use this flaw for example to read / write
root GID accessible files, if the particular web application provided remote
means for local file manipulation. |
| Alerts: |
|
( Log in to post comments)
|
|
|