First published: Tue Nov 19 2019(Updated: )
surf: cookie jar has read access from other local user
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/surf | 2.0+git20201107-2 2.1+git20221016-4 2.1+git20221016-6 | |
surf | <0.5 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 | |
Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0842 is classified as a medium-severity vulnerability due to improper permission settings.
To fix CVE-2012-0842, update the surf package to versions 2.0+git20201107-2, 2.1+git20221016-4, or 2.1+git20221016-6.
CVE-2012-0842 impacts the surf web browser allowing unauthorized local read access to the cookie jar.
CVE-2012-0842 specifically affects Debian GNU/Linux versions 8.0, 9.0, and 10.0.
Users of the surf web browser on Debian systems are primarily affected by CVE-2012-0842.