← Back

CVE-2012-4442

nvd nist
Published: Oct 5, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.7
Vector
AV:L/AC:M/Au:N/C:C/I:N/A:N
Exploitability: 3.4 / Impact: 6.9
Source: NVD

Description

Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.

Affected (1)

Monkey
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.9.3

Related CWEs

References (6)

Timeline

No history available yet.