Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.
{ "binaries": [ { "binary_name": "evolution", "binary_version": "3.18.5.2-0ubuntu3.2" }, { "binary_name": "evolution-common", "binary_version": "3.18.5.2-0ubuntu3.2" }, { "binary_name": "evolution-dev", "binary_version": "3.18.5.2-0ubuntu3.2" }, { "binary_name": "evolution-plugins", "binary_version": "3.18.5.2-0ubuntu3.2" }, { "binary_name": "evolution-plugins-experimental", "binary_version": "3.18.5.2-0ubuntu3.2" }, { "binary_name": "libevolution", "binary_version": "3.18.5.2-0ubuntu3.2" } ] }
{ "binaries": [ { "binary_name": "evolution", "binary_version": "3.28.5-0ubuntu0.18.04.2" }, { "binary_name": "evolution-common", "binary_version": "3.28.5-0ubuntu0.18.04.2" }, { "binary_name": "evolution-dev", "binary_version": "3.28.5-0ubuntu0.18.04.2" }, { "binary_name": "evolution-plugin-bogofilter", "binary_version": "3.28.5-0ubuntu0.18.04.2" }, { "binary_name": "evolution-plugin-pstimport", "binary_version": "3.28.5-0ubuntu0.18.04.2" }, { "binary_name": "evolution-plugin-spamassassin", "binary_version": "3.28.5-0ubuntu0.18.04.2" }, { "binary_name": "evolution-plugins", "binary_version": "3.28.5-0ubuntu0.18.04.2" }, { "binary_name": "evolution-plugins-experimental", "binary_version": "3.28.5-0ubuntu0.18.04.2" }, { "binary_name": "libevolution", "binary_version": "3.28.5-0ubuntu0.18.04.2" } ] }
{ "binaries": [ { "binary_name": "evolution", "binary_version": "3.36.5-0ubuntu1" }, { "binary_name": "evolution-common", "binary_version": "3.36.5-0ubuntu1" }, { "binary_name": "evolution-dev", "binary_version": "3.36.5-0ubuntu1" }, { "binary_name": "evolution-plugin-bogofilter", "binary_version": "3.36.5-0ubuntu1" }, { "binary_name": "evolution-plugin-pstimport", "binary_version": "3.36.5-0ubuntu1" }, { "binary_name": "evolution-plugin-spamassassin", "binary_version": "3.36.5-0ubuntu1" }, { "binary_name": "evolution-plugins", "binary_version": "3.36.5-0ubuntu1" }, { "binary_name": "evolution-plugins-experimental", "binary_version": "3.36.5-0ubuntu1" }, { "binary_name": "libevolution", "binary_version": "3.36.5-0ubuntu1" } ] }
{ "binaries": [ { "binary_name": "evolution", "binary_version": "3.44.4-0ubuntu2" }, { "binary_name": "evolution-common", "binary_version": "3.44.4-0ubuntu2" }, { "binary_name": "evolution-dev", "binary_version": "3.44.4-0ubuntu2" }, { "binary_name": "evolution-plugin-bogofilter", "binary_version": "3.44.4-0ubuntu2" }, { "binary_name": "evolution-plugin-pstimport", "binary_version": "3.44.4-0ubuntu2" }, { "binary_name": "evolution-plugin-spamassassin", "binary_version": "3.44.4-0ubuntu2" }, { "binary_name": "evolution-plugins", "binary_version": "3.44.4-0ubuntu2" }, { "binary_name": "evolution-plugins-experimental", "binary_version": "3.44.4-0ubuntu2" }, { "binary_name": "libevolution", "binary_version": "3.44.4-0ubuntu2" } ] }
{ "binaries": [ { "binary_name": "evolution", "binary_version": "3.52.3-0ubuntu1" }, { "binary_name": "evolution-common", "binary_version": "3.52.3-0ubuntu1" }, { "binary_name": "evolution-dev", "binary_version": "3.52.3-0ubuntu1" }, { "binary_name": "evolution-plugin-bogofilter", "binary_version": "3.52.3-0ubuntu1" }, { "binary_name": "evolution-plugin-pstimport", "binary_version": "3.52.3-0ubuntu1" }, { "binary_name": "evolution-plugin-spamassassin", "binary_version": "3.52.3-0ubuntu1" }, { "binary_name": "evolution-plugins", "binary_version": "3.52.3-0ubuntu1" }, { "binary_name": "evolution-plugins-experimental", "binary_version": "3.52.3-0ubuntu1" }, { "binary_name": "libevolution", "binary_version": "3.52.3-0ubuntu1" } ] }
{ "binaries": [ { "binary_name": "evolution", "binary_version": "3.56.0-1" }, { "binary_name": "evolution-common", "binary_version": "3.56.0-1" }, { "binary_name": "evolution-dev", "binary_version": "3.56.0-1" }, { "binary_name": "evolution-plugin-bogofilter", "binary_version": "3.56.0-1" }, { "binary_name": "evolution-plugin-pstimport", "binary_version": "3.56.0-1" }, { "binary_name": "evolution-plugin-spamassassin", "binary_version": "3.56.0-1" }, { "binary_name": "evolution-plugins", "binary_version": "3.56.0-1" }, { "binary_name": "evolution-plugins-experimental", "binary_version": "3.56.0-1" }, { "binary_name": "libevolution", "binary_version": "3.56.0-1" } ] }