An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).
{ "availability": "No subscription required", "ubuntu_priority": "negligible", "binaries": [ { "binary_name": "libtspi-dev", "binary_version": "0.3.15-0.2" }, { "binary_name": "libtspi1", "binary_version": "0.3.15-0.2" }, { "binary_name": "trousers", "binary_version": "0.3.15-0.2" }, { "binary_name": "trousers-dbg", "binary_version": "0.3.15-0.2" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "negligible", "binaries": [ { "binary_name": "libtspi-dev", "binary_version": "0.3.15-0.3" }, { "binary_name": "libtspi1", "binary_version": "0.3.15-0.3" }, { "binary_name": "trousers", "binary_version": "0.3.15-0.3" }, { "binary_name": "trousers-dbg", "binary_version": "0.3.15-0.3" } ] }