zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2005-01-24 05:00
Updated : 2017-07-11 01:32
NVD link : CVE-2005-0072
Mitre link : CVE-2005-0072
CVE.ORG link : CVE-2005-0072
JSON object : View
Products Affected
                ejoy_and_hu_yong
- zhcon
 
CWE
                