MEDIUM
Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check
Published Oct 5, 2012
4.7
MEDIUMCVSS 2.0
EPSS 0.31%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.