Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.
Advisories
Source ID Title
EUVD EUVD EUVD-2012-0025 Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.
Github GHSA Github GHSA GHSA-27px-qpmj-qg38 Paste Script has improper group memberships permissions
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T18:38:15.020Z

Reserved: 2012-01-19T00:00:00

Link: CVE-2012-0878

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-05-01T19:55:01.910

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-0878

cve-icon Redhat

Severity : Moderate

Publid Date: 2012-02-06T00:00:00Z

Links: CVE-2012-0878 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses