First published: Sat Jan 27 2007(Updated: )
The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissions and might allow local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rpath Linux | =1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0536 is categorized as a high severity vulnerability due to its potential to allow local users to gain elevated privileges.
To fix CVE-2007-0536, ensure that you update rMake to a secure version that properly drops supplemental groups.
CVE-2007-0536 affects rPath Linux version 1, particularly the chroot helper component.
The risks include the possibility of local users installing packages with insecure permissions, leading to privilege escalation.
You can determine vulnerability by checking if your system is running rPath Linux version 1 with the affected version of rMake.