CVE-2013-6889
GNU Rush 1.7 - Unauthenticated Arbitrary File Read via --lint Option
Title source: llmDescription
GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option.
References (2)
Core 2
Core References
Exploit x_refsource_confirm
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733505
Various Sources x_refsource_confirm
http://git.gnu.org.ua/gitweb?p=rush.git%3Ba=commit%3Bh=00bdccd429517f12dbf37ab4397ddec3e51a2738
Scores
EPSS
0.0006
EPSS Percentile
17.8%
Details
CWE
CWE-264
Status
published
Products (1)
gnu/rush
1.7
Published
May 08, 2014
Tracked Since
Feb 18, 2026