FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

security/trousers -- several vulnerabilities

Affected packages
trousers < 0.3.14_3

Details

VuXML ID e37a0a7b-e1a7-11ea-9538-0c9d925bbbc0
Discovery 2020-05-20
Entry 2020-08-18

the TrouSerS project reports reports:

If the tcsd daemon is started with root privileges, it fails to drop the root gid after it is no longer needed.

If the tcsd daemon is started with root privileges, the tss user has read and write access to the /etc/tcsd.conf file.

If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks.

References

CVE Name CVE-2020-24330
CVE Name CVE-2020-24331
CVE Name CVE-2020-24332
URL https://sourceforge.net/p/trousers/trousers/ci/e74dd1d96753b0538192143adf58d04fcd3b242b/
URL https://www.openwall.com/lists/oss-security/2020/05/20/3