{"id":"CVE-2009-3289","details":"The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.","modified":"2026-04-10T03:40:54.697989Z","published":"2009-09-22T10:30:00Z","references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html"},{"type":"ADVISORY","url":"http://secunia.com/advisories/39656"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2009/09/08/8"},{"type":"EVIDENCE","url":"https://bugs.launchpad.net/ubuntu/+source/glib2.0/+bug/418135"},{"type":"EVIDENCE","url":"https://bugzilla.gnome.org/show_bug.cgi?id=593406"},{"type":"REPORT","url":"http://www.vupen.com/english/advisories/2010/1001"},{"type":"REPORT","url":"https://bugs.launchpad.net/ubuntu/+source/glib2.0/+bug/418135"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=593406"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}