RSS   Vulnerabilities for 'Trousers'   RSS

2020-08-13
 
CVE-2020-24331

CWE-732
 

 
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).

 
 
CVE-2020-24330

CWE-732
 

 
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.

 


Copyright 2024, cxsecurity.com

 

Back to Top