CVE-2005-2807

NameCVE-2005-2807
Descriptionfrox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
froxsource(unstable)(not affected)

Notes

- frox <not-affected> (does not run setuid root in the Debian package)

Search for package or bug name: Reporting problems