Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2007-0557

Disclosure Date: January 29, 2007 (last updated October 04, 2023)
rMake before 1.0.4 drops root privileges in a way that retains the original supplemental groups, which might allow attackers to gain privileges via a crafted recipe file, a different vulnerability than CVE-2007-0536.
0
Attacker Value
Unknown

CVE-2007-0536

Disclosure Date: January 27, 2007 (last updated October 04, 2023)
The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissions and might allow local users to gain privileges.
0