4.9
CVSSv2

CVE-2013-6889

Published: 08/05/2014 Updated: 07/11/2023
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu rush 1.7

Vendor Advisories

Debian Bug report logs - #733505 rush: CVE-2013-6889: Allows reading arbitrary files Package: rush; Maintainer for rush is Mats Erik Andersson <matsandersson@gisladiskerse>; Source for rush is src:rush (PTS, buildd, popcon) Reported by: Steve Kemp <steve@steveorguk> Date: Sun, 29 Dec 2013 14:48:02 UTC Severity: ...