CVE Vulnerabilities

CVE-2009-3589

Published: Oct 08, 2009 | Modified: Oct 08, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

incron 0.5.5 does not initialize supplementary groups when running a process from a users incrontabs, which causes the process to be run with the incrond supplementary groups and allows local users to gain privileges via an incrontab table.

Affected Software

Name Vendor Start Version End Version
Incron Inotify 0.5.5 (including) 0.5.5 (including)
Incron Ubuntu intrepid *
Incron Ubuntu jaunty *
Incron Ubuntu karmic *

References