4.7
CVSSv2

CVE-2012-4442

Published: 05/10/2012 Updated: 26/03/2020
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
VMScore: 418
Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.

Vulnerable Product Search on Vulmon Subscribe to Product

monkey-project monkey 0.9.3