CVE-2009-3289
published 2009-09-22CVE-2009-3289: The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users…
PriorityP430high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.36%
28.2th percentile
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glib2.0 | < glib2.0 2.22.0-1 (bookworm) | glib2.0 2.22.0-1 (bookworm) |
| gnome | glib | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GLib vulnerability
vendor_ubuntu·2009-10-05
CVE-2009-3289 GLib vulnerability
Title: GLib vulnerability
Summary: GLib vulnerability
Arand Nash discovered that applications linked to GLib (e.g. Nautilus)
did not correctly copy symlinks. If a user copied symlinks with GLib,
the symlink target files would become world-writable, allowing local
attackers to gain access to potentially sensitive information.
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Red Hat
glib2: folder | symlink permissions change after copy via nautilus
vendor_redhat·2009-08-28·CVSS 7.8
CVE-2009-3289 [HIGH] glib2: folder | symlink permissions change after copy via nautilus
glib2: folder | symlink permissions change after copy via nautilus
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
Statement: Not vulnerable. This issue does not affect the versions of glib2 as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Debian
CVE-2009-3289: glib2.0 - The g_file_copy function in glib 2.0 sets the permissions of a target file to th...
vendor_debian·2009·CVSS 7.8
CVE-2009-3289 [HIGH] CVE-2009-3289: glib2.0 - The g_file_copy function in glib 2.0 sets the permissions of a target file to th...
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
Scope: local
bookworm: resolved (fixed in 2.22.0-1)
bullseye: resolved (fixed in 2.22.0-1)
forky: resolved (fixed in 2.22.0-1)
sid: resolved (fixed in 2.22.0-1)
trixie: resolved (fixed in 2.22.0-1)
GHSA
GHSA-q7q8-g4m3-j3pq: The g_file_copy function in glib 2
ghsa_unreviewed·2022-05-02
CVE-2009-3289 [MEDIUM] CWE-732 GHSA-q7q8-g4m3-j3pq: The g_file_copy function in glib 2
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
OSV
CVE-2009-3289: The g_file_copy function in glib 2
osv·2009-09-22·CVSS 7.8
CVE-2009-3289 [HIGH] CVE-2009-3289: The g_file_copy function in glib 2
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.htmlhttp://secunia.com/advisories/39656http://www.openwall.com/lists/oss-security/2009/09/08/8http://www.vupen.com/english/advisories/2010/1001https://bugs.launchpad.net/ubuntu/+source/glib2.0/+bug/418135https://bugzilla.gnome.org/show_bug.cgi?id=593406http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.htmlhttp://secunia.com/advisories/39656http://www.openwall.com/lists/oss-security/2009/09/08/8http://www.vupen.com/english/advisories/2010/1001https://bugs.launchpad.net/ubuntu/+source/glib2.0/+bug/418135https://bugzilla.gnome.org/show_bug.cgi?id=593406
2009-09-22
Published