5.1
CVSSv2

CVE-2012-0878

Published: 01/05/2012 Updated: 02/04/2013
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Paste Script 1.7.5 and previous versions does not properly set group memberships during execution with root privileges, which might allow remote malicious users to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.

Vulnerable Product Search on Vulmon Subscribe to Product

pythonpaste paste

Vendor Advisories

Synopsis Moderate: python-paste-script security update Type/Severity Security Advisory: Moderate Topic An updated python-paste-script package that fixes one security issue is nowavailable for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impac ...
Debian Bug report logs - #661061 python-paste-script: Supplementary groups not dropped when started an application with "paster serve" as root Package: src:pastescript; Maintainer for src:pastescript is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Nico Golde <nion@debianorg> ...