The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.
Name | Vendor | Start Version | End Version |
---|---|---|---|
App-crypt_pinentry | Gentoo | 0.7.2 (including) | 0.7.2 (including) |
App-crypt_pinentry | Gentoo | 0.7.2-r1 (including) | 0.7.2-r1 (including) |