SilverCity: Insecure file permissions
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200506-05 / silvercity |
| Release Date |
June 08, 2005 |
| Latest Revision |
May 22, 2006: 02 |
| Impact |
normal |
| Exploitable |
local |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| app-text/silvercity |
<
0.9.5-r1 |
>=
0.9.5-r1 |
All supported architectures
|
Related bugreports:
#93558
Synopsis
Executable files with insecure permissions can be modified causing an
unsuspecting user to run arbitrary code.
2.
Impact Information
Background
SilverCity provides lexical analysis for over 20 programming and markup
languages.
Description
The SilverCity package installs three executable files with insecure
permissions.
Impact
A local attacker could modify the executable files, causing arbitrary
code to be executed with the permissions of an unsuspecting SilverCity
user.
3.
Resolution Information
Workaround
There are no known workarounds at this time.
Resolution
All SilverCity users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-text/silvercity-0.9.5-r1"
|
4.
References
|