oss-sec mailing list archives

CVE Request - glib symlink copying permission exposure


From: Kees Cook <kees () ubuntu com>
Date: Tue, 8 Sep 2009 16:13:46 -0700

Hi,

I'd like to request a CVE for an issue where glib causes symlink targets
to gain 0777 permissions when any symlink pointing at the target is
copied.  There is no privilege escalation, but it can lead to situations
where other users on a system could have read/write access to important
files (e.g. .ssh/id_rsa).

https://bugs.launchpad.net/bugs/418135
http://bugzilla.gnome.org/show_bug.cgi?id=593406

Thanks,

-Kees

-- 
Kees Cook
Ubuntu Security Team


Current thread: