Beveiligingsadvies

CVE-2012-4442

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2012-10-05 21:00:00
Laatst bijgewerkt 2024-09-17 04:03:42
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.