CVE-2013-6889
GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0006 (0.1%)
Percentile: 17.5%
EPSS: 2026-05-06
Affects
gnu:rushTechnical description
GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option.
Published: 5/8/2014, 2:29:12 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://git.gnu.org.ua/gitweb?p=rush.git%3Ba=commit%3Bh=00bdccd429517f12dbf37ab4397ddec3e51a2738
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733505
- http://git.gnu.org.ua/gitweb?p=rush.git%3Ba=commit%3Bh=00bdccd429517f12dbf37ab4397ddec3e51a2738
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733505