Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2005-0072
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-0072

Description:
zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/19045

ST
  1012977

SAID
  Secunia Advisory: SA13987
  Secunia Advisory: SA13977
  Secunia Advisory: SA13982

MANDRAKE
  http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:012

DEBIAN
  http://www.debian.org/security/2005/dsa-655

BID
  12343


Return to the previous page.