Gentoo ChessBrain EBuild Insecure Default Permissions Vulnerability
BID:11700
Info
Gentoo ChessBrain EBuild Insecure Default Permissions Vulnerability
| Bugtraq ID: | 11700 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 17 2004 12:00AM |
| Updated: | Nov 17 2004 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
Gentoo ChessBrain EBuild Insecure Default Permissions Vulnerability
The Gentoo ChessBrain eBuild package is reported prone to a weak default permissions vulnerability.
A local attacker may exploit this vulnerability to escalate privileges.
The Gentoo ChessBrain eBuild package is reported prone to a weak default permissions vulnerability.
A local attacker may exploit this vulnerability to escalate privileges.
Exploit / POC
Gentoo ChessBrain EBuild Insecure Default Permissions Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Gentoo ChessBrain EBuild Insecure Default Permissions Vulnerability
Solution:
Gentoo has released an advisory (GLSA 200411-26) to address this and other related issues. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=app-sci/chessbrain-20407-r1"
Solution:
Gentoo has released an advisory (GLSA 200411-26) to address this and other related issues. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=app-sci/chessbrain-20407-r1"
References
Gentoo ChessBrain EBuild Insecure Default Permissions Vulnerability
References:
References:
- ChessBrain Home Page (ChessBrain)