eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Eject | Eject | 2.0.10 (including) | 2.0.10 (including) |
Eject | Eject | 2.0.11 (including) | 2.0.11 (including) |
Eject | Eject | 2.0.12 (including) | 2.0.12 (including) |