LWN.net Logo

python-paste-script: insecure root GID accessible files

Package(s):python-paste-script CVE #(s):CVE-2012-0878
Created:April 9, 2012 Updated:August 28, 2012
Description: From the Red Hat bugzilla:

A security flaw was found in the way Paster, a pluggable command-line frontend, when started as root (for example to have access to privileged port) to serve a web based application, performed privileges dropping upon startup (supplementary groups were not dropped properly regardless of the UID, GID specified in the .ini configuration file or in the --user and --group CL arguments). A remote attacker could use this flaw for example to read / write root GID accessible files, if the particular web application provided remote means for local file manipulation.

Alerts:
Fedora FEDORA-2012-2418 2012-04-06
Fedora FEDORA-2012-2413 2012-04-06
Red Hat RHSA-2012:1206-01 2012-08-27
CentOS CESA-2012:1206 2012-08-27
Oracle ELSA-2012-1206 2012-08-27
Scientific Linux SL-pyth-20120827 2012-08-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds