First published: Sun Dec 29 2013(Updated: )
GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/rush | 1.8+dfsg-1.1 2.3-1 | |
GNU Rush | =1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6889 has a medium severity rating due to the improper privilege dropping that can lead to local file reading.
To fix CVE-2013-6889, upgrade to GNU Rush version 1.8+dfsg-1.1 or 2.3-1.
CVE-2013-6889 allows local users to read arbitrary files, potentially compromising the confidentiality of sensitive information.
CVE-2013-6889 affects users running GNU Rush version 1.7 operating on Debian systems.
No official workaround exists for CVE-2013-6889; upgrading to a fixed version is the recommended solution.