LWN.net Logo

davfs2: privilege escalation

Package(s):davfs2 CVE #(s):CVE-2013-4362
Created:September 27, 2013 Updated:October 2, 2013
Description:

From the Debian advisory:

Davfs2, a filesystem client for WebDAV, calls the function system() insecurely while is setuid root. This might allow a privilege escalation.

Alerts:
Debian DSA-2765-1 2013-09-26
Mandriva MDVSA-2013:244 2013-09-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds