Описание
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2016-3067
- https://cygwin.com/ml/cygwin-announce/2016-02/msg00023.html
- https://cygwin.com/ml/cygwin-announce/2016-04/msg00020.html
- https://cygwin.com/ml/cygwin-announce/2016-04/msg00054.html
- https://cygwin.com/ml/cygwin/2016-02/msg00129.html
- https://sourceware.org/git/?p=newlib-cygwin.git%3Ba=commit%3Bh=205862ed08649df8f50b926a2c58c963f571b044
- https://sourceware.org/git/?p=newlib-cygwin.git;a=commit;h=205862ed08649df8f50b926a2c58c963f571b044
Связанные уязвимости
CVSS3: 9.8
nvd
почти 9 лет назад
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.