Incorrect default permissions in colord-debugsource - #VU97225

 

Incorrect default permissions in colord-debugsource - #VU97225

Published: September 12, 2024


Vulnerability identifier: #VU97225
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a presence of a script that changes the ownership of /var/lib/colord. A local user can escalate privileges on the system.


Affected software

colord-debugsource
libcolord-devel
typelib-1_0-Colorhug-1_0
typelib-1_0-Colord-1_0
colord-debuginfo
libcolorhug2
libcolord2-debuginfo
libcolorhug2-debuginfo
libcolord2
libcolord2-32bit
libcolord2-debuginfo-32bit
colord
colord-lang
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Workstation Extension 12

Remediation

Install updates from vendor's website.

colord-debugsource - update to 1.3.3-13.6.1
libcolord-devel - update to 1.3.3-13.6.1
typelib-1_0-Colorhug-1_0 - update to 1.3.3-13.6.1
typelib-1_0-Colord-1_0 - update to 1.3.3-13.6.1
colord-debuginfo - update to 1.3.3-13.6.1
libcolorhug2 - update to 1.3.3-13.6.1
libcolord2-debuginfo - update to 1.3.3-13.6.1
libcolorhug2-debuginfo - update to 1.3.3-13.6.1
libcolord2 - update to 1.3.3-13.6.1
libcolord2-32bit - update to 1.3.3-13.6.1
libcolord2-debuginfo-32bit - update to 1.3.3-13.6.1
colord - update to 1.3.3-13.6.1
colord-lang - update to 1.3.3-13.6.1

External References

Related Security Bulletins