« List of all CVEs

CVE-2009-3289

Published: 9/22/2009 Last updated: 8/7/2024 Reserved: 9/22/2009

The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (1)

conf-glib-2

Products affected (1)

Product Vendor Version
n/a n/a <= 3.08.02

References (12)