CVE-2009-3289
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- gnome/glib · opensuse/opensuse · suse/suse linux enterprise server
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/39656Broken Link
- http://www.openwall.com/lists/oss-security/2009/09/08/8Mailing List
- http://www.vupen.com/english/advisories/2010/1001Permissions Required
- https://bugs.launchpad.net/ubuntu/+source/glib2.0/+bug/418135Exploit, Issue Tracking
- https://bugzilla.gnome.org/show_bug.cgi?id=593406Exploit, Issue Tracking
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/39656Broken Link
- http://www.openwall.com/lists/oss-security/2009/09/08/8Mailing List
- http://www.vupen.com/english/advisories/2010/1001Permissions Required
- https://bugs.launchpad.net/ubuntu/+source/glib2.0/+bug/418135Exploit, Issue Tracking
- https://bugzilla.gnome.org/show_bug.cgi?id=593406Exploit, Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.