CVE-2012-4442: Race Condition
Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4442?
CVE-2012-4442 is categorized as a moderate severity vulnerability due to the potential for local users to bypass file-read restrictions.
How do I fix CVE-2012-4442?
To fix CVE-2012-4442, it is recommended to upgrade Monkey HTTP Daemon to a version higher than 0.9.3 or apply any available security patches.
Who is affected by CVE-2012-4442?
CVE-2012-4442 affects systems running Monkey HTTP Daemon version 0.9.3.
What type of vulnerability is CVE-2012-4442?
CVE-2012-4442 is a race condition vulnerability that can lead to unauthorized file access.
Can CVE-2012-4442 be exploited remotely?
CVE-2012-4442 is not a remote exploitation vulnerability, as it requires local user access to be exploited.