incron 0.5.5 does not initialize supplementary groups when running a process from a users incrontabs, which causes the process to be run with the incrond supplementary groups and allows local users to gain privileges via an incrontab table.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Incron | Inotify | 0.5.5 (including) | 0.5.5 (including) |
Incron | Ubuntu | intrepid | * |
Incron | Ubuntu | jaunty | * |
Incron | Ubuntu | karmic | * |