Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://blog.torproject.org/blog/tor-0.2.0.32-released - | |
References | () http://secunia.com/advisories/33025 - Vendor Advisory | |
References | () http://secunia.com/advisories/34583 - | |
References | () http://security.gentoo.org/glsa/glsa-200904-11.xml - | |
References | () http://www.securityfocus.com/bid/32648 - Patch | |
References | () http://www.vupen.com/english/advisories/2008/3366 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/47101 - |
Information
Published : 2008-12-09 00:30
Updated : 2024-11-21 00:54
NVD link : CVE-2008-5397
Mitre link : CVE-2008-5397
CVE.ORG link : CVE-2008-5397
JSON object : View
Products Affected
tor
- tor
CWE
CWE-264
Permissions, Privileges, and Access Controls