cvelist/2008/5xxx/CVE-2008-5397.json

93 lines
2.6 KiB
JSON

{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2008-5397",
"STATE" : "PUBLIC"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a",
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
},
"vendor_name" : "n/a"
}
]
}
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "n/a"
}
]
}
]
},
"references" : {
"reference_data" : [
{
"name" : "http://blog.torproject.org/blog/tor-0.2.0.32-released",
"refsource" : "CONFIRM",
"url" : "http://blog.torproject.org/blog/tor-0.2.0.32-released"
},
{
"name" : "GLSA-200904-11",
"refsource" : "GENTOO",
"url" : "http://security.gentoo.org/glsa/glsa-200904-11.xml"
},
{
"name" : "32648",
"refsource" : "BID",
"url" : "http://www.securityfocus.com/bid/32648"
},
{
"name" : "34583",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/34583"
},
{
"name" : "ADV-2008-3366",
"refsource" : "VUPEN",
"url" : "http://www.vupen.com/english/advisories/2008/3366"
},
{
"name" : "33025",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/33025"
},
{
"name" : "tor-user-privilege-escalation(47101)",
"refsource" : "XF",
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/47101"
}
]
}
}