CVE-2012-2760

Publication date

2012-07-25 19:00:00

Family

mitre

State

PUBLISHED

Description

mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.