Lucene search

K
cveRedhatCVE-2012-4442
HistoryOct 05, 2012 - 9:55 p.m.

CVE-2012-4442

2012-10-0521:55:01
CWE-264
redhat
web.nvd.nist.gov
25
cve-2012-4442
monkey http daemon
security vulnerability
file permissions
race condition

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

5.1%

Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.

Affected configurations

Nvd
Node
monkey-projectmonkeyMatch0.9.3
VendorProductVersionCPE
monkey-projectmonkey0.9.3cpe:2.3:a:monkey-project:monkey:0.9.3:*:*:*:*:*:*:*

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2012-4442