First published: Tue Sep 22 2009(Updated: )
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME GLib | =2.0 | |
openSUSE openSUSE | =11.0 | |
openSUSE openSUSE | =11.1 | |
SUSE SUSE Linux Enterprise Server | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.