FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0072

This CVE name corresponds to:

Entered Topic
2005-01-25 zhcon -- unauthorized file access

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0072
Phase Assigned(20050114)

Description

zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.

References

Source Reference
DEBIAN DSA-655
MANDRAKE MDKSA-2005:012
BID 12343
SECTRACK 1012977
SECUNIA 13977
SECUNIA 13982
SECUNIA 13987
XF zhcon-information-disclosure(19045)