CHUID Privileged File Owner Changing Vulnerability

chuid is a freely available, open source user id changing utility. It was written and is maintained by Scott Parish. It is designed for use on the Linux operating system.

chuid does not properly handle user-supplied input. Due to insufficient checking of user input, it is possible for a remote user to change the ownership of a file owned by a privileged user. This could allow a remote user to change the ownership or group membership of a restricted or privileged file.


 

Privacy Statement
Copyright 2010, SecurityFocus