Описание
Icecast before 2.4.0 does not change the supplementary group privileges when is configured, which allows local users to gain privileges via unspecified vectors.
Icecast before 2.4.0 does not change the supplementary group privileges when is configured, which allows local users to gain privileges via unspecified vectors.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-9091
- https://bugzilla.redhat.com/show_bug.cgi?id=1168146
- https://trac.xiph.org/changeset/19137
- http://icecast.org/news/icecast-release-2_4_0
- http://lists.opensuse.org/opensuse-updates/2014-12/msg00037.html
- http://seclists.org/oss-sec/2014/q4/794
- http://seclists.org/oss-sec/2014/q4/802
EPSS
CVE ID
Связанные уязвимости
Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors.
Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors.
Icecast before 2.4.0 does not change the supplementary group privilege ...
EPSS