Monotone 0.25 and earlier, when a user creates a file in a directory called "mt", and when checking out that file on a case-insensitive file system such as Windows or Mac OS X, places the file into the "MT" bookkeeping directory, which could allow context-dependent attackers to execute arbitrary Lua programs as the user running monotone.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2006-03-12T21:00:00

Updated: 2017-07-19T15:57:01

Reserved: 2006-03-12T00:00:00


Link: CVE-2006-1166

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2006-03-12T21:02:00.000

Modified: 2017-07-20T01:30:22.067


Link: CVE-2006-1166

JSON object: View

cve-icon Redhat Information

No data.