It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.
References
Information
Published : 2018-01-09 13:29
Updated : 2023-02-12 15:28
NVD link : CVE-2017-15131
Mitre link : CVE-2017-15131
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
freedesktop
- xdg-user-dirs
redhat
- enterprise_linux