An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).
{ "availability": "No subscription required", "ubuntu_priority": "negligible", "binaries": [ { "binary_version": "0.3.15-0.2", "binary_name": "libtspi-dev" }, { "binary_version": "0.3.15-0.2", "binary_name": "libtspi1" }, { "binary_version": "0.3.15-0.2", "binary_name": "trousers" }, { "binary_version": "0.3.15-0.2", "binary_name": "trousers-dbg" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "negligible", "binaries": [ { "binary_version": "0.3.15-0.3", "binary_name": "libtspi-dev" }, { "binary_version": "0.3.15-0.3", "binary_name": "libtspi1" }, { "binary_version": "0.3.15-0.3", "binary_name": "trousers" }, { "binary_version": "0.3.15-0.3", "binary_name": "trousers-dbg" } ] }