CVE-2012-0878Medium· 6.5▾ SunlitPaste Script has improper group memberships permissions
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
4.0%
Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.
pastescript < 2.0.1paste < 1.7.5.1Upgrade to a patched release:
pastescript 2.0.1paste 1.7.5.1