First published: Mon Mar 20 2006(Updated: )
chpst in runit 1.3.3-1 for Debian GNU/Linux, when compiled on little endian i386 machines against dietlibc, does not properly handle when multiple groups are specified in the -u option, which causes chpst to assign permissions for the root group due to inconsistent bit sizes for the gid_t type.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runit | =1.3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1319 has been rated as a medium severity vulnerability affecting runit 1.3.3-1 on Debian GNU/Linux.
To fix CVE-2006-1319, upgrade to a version of runit that is not affected by this vulnerability.
CVE-2006-1319 impacts Debian GNU/Linux systems running runit version 1.3.3-1 compiled on little endian i386 architectures.
CVE-2006-1319 exploits improper handling of multiple groups in the -u option of chpst, leading to permission escalation.
Primarily, users and administrators of Debian GNU/Linux systems utilizing runit 1.3.3-1 are affected by CVE-2006-1319.