Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-12-08 16:30
Updated : 2017-08-07 18:33
NVD link : CVE-2008-5397
Mitre link : CVE-2008-5397
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
tor
- tor