MEDIUM · 4.7

CVE-2012-4442

Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restriction...

Vulnerability Description

Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.

CVSS Score

4.7

MEDIUM

AV:L/AC:M/Au:N/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Monkey-ProjectMonkey0.9.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-4442?

CVE-2012-4442 is a vulnerability with a CVSS score of 4.7 (MEDIUM). Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restriction...

How severe is CVE-2012-4442?

CVE-2012-4442 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-4442?

Check the references section above for vendor advisories and patch information. Affected products include: Monkey-Project Monkey.