Vulnerabilities (CVE)

Filtered by vendor Steven Schaefer Subscribe
Filtered by product Sophster
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2611 1 Steven Schaefer 1 Sophster 2024-02-28 4.6 MEDIUM N/A
The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.