The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade glib2.0 | Jul 30, 2024 | Sep 22, 2009 |
| Suse | — | Upgrade libgio-2_0-0-32bitUpgrade libglib-2_0-0Upgrade libgmodule-2_0-0Upgrade libgmodule-2_0-0-32bitUpgrade libgthread-2_0-0-x86Upgrade libgmodule-2_0-0-x86Upgrade libgthread-2_0-0Upgrade libglib-2_0-0-32bitUpgrade libglib-2_0-0-x86Upgrade libgio-2_0-0Upgrade glib2-docUpgrade libgobject-2_0-0-32bitUpgrade glib2Upgrade libgobject-2_0-0Upgrade libgthread-2_0-0-32bitUpgrade libgobject-2_0-0-x86Upgrade glib2-langUpgrade libgio-2_0-0-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libglib2.0-0 | Nov 8, 2024 | Sep 22, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub