Vulnerability in zdaemon 2.0.5 and earlier
7 Jun
2012
7 Jun
'12
8:12 p.m.
zdaemon is a Unix (Unix, Linux, Mac OS X) Python program that wraps commands to make them behave as proper daemons. See http://pypi.python.org/pypi/zdaemon. zdaemon can be configured to start as root and then switch to a less privileged user. In version 2.0.5 and earlier, zdaemon didn't update supplementary groups. Processes started as root retain root's supplementary groups, likely providing more privileges than intended. This is fixed by zdaemon 2.0.6. It's recommended that people using zdaemon 2.0.5 and earlier upgrade to 2.0.6 at their earliest convenience. -- Jim Fulton
5074
Age (days ago)
5074
Last active (days ago)
0 comments
1 participants
participants (1)
-
Jim Fulton