First published: Fri Dec 06 2013(Updated: )
The SUSE horde5 package before 5.0.2-2.4.1 sets incorrect ownership for certain configuration files and directories including /etc/apache2/vhosts.d, which allows local wwwrun users to gain privileges via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1090 is considered to be of medium severity due to improper ownership settings allowing privilege escalation for local users.
To fix CVE-2013-1090, ensure that the ownership and permissions of the affected configuration files and directories are properly set for security.
The vulnerability affects users of the SUSE horde5 package prior to version 5.0.2-2.4.1 on openSUSE 12.3.
The risks associated with CVE-2013-1090 include potential privilege escalation in a local environment, allowing unauthorized actions by wwwrun users.
CVE-2013-1090 is primarily a local privilege escalation vulnerability and does not involve remote exploitation.