Jump to content

Advisories MDVSA-2010:077: nss_db


paul
 Share

Recommended Posts

A vulnerability has been found and corrected in nss_db:

 

The Free Software Foundation (FSF) Berkeley DB NSS module (aka

libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working

directory, which allows local users to obtain sensitive information

via a symlink attack involving a setgid or setuid application that

uses this module (CVE-2010-0826).

 

The updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...