Incorrect Execution-Assigned Permissions |
Weakness ID: 279 (Weakness Variant) | Status: Draft |
Description Summary
While it is executing, the software sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.
Reference | Description |
---|---|
CVE-2002-0265 | Log files opened read/write. |
CVE-2003-0876 | Log files opened read/write. |
CVE-2002-1694 | Log files opened read/write. |
Very carefully manage the setting, management and handling of permissions. Explicitly manage trust zones in the software. |
Phase: Architecture and Design Ensure that appropriate compartmentalization is built into the system design and that the compartmentalization serves to allow for and further reinforce privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide when it is appropriate to use and to drop system privileges. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 275 | Permission Issues | Development Concepts (primary)699 |
ChildOf | ![]() | 732 | Incorrect Permission Assignment for Critical Resource | Research Concepts (primary)1000 |
ChildOf | ![]() | 743 | CERT C Secure Coding Section 09 - Input Output (FIO) | Weaknesses Addressed by the CERT C Secure Coding Standard (primary)734 |
Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
---|---|---|---|
PLOVER | Insecure execution-assigned permissions | ||
CERT C Secure Coding | FIO06-C | Create files with appropriate access permissions |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
PLOVER | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Relationships, Taxonomy Mappings | ||||
2008-11-24 | CWE Content Team | MITRE | Internal | |
updated Relationships, Taxonomy Mappings | ||||
2009-05-27 | CWE Content Team | MITRE | Internal | |
updated Description, Name | ||||
Previous Entry Names | ||||
Change Date | Previous Entry Name | |||
2009-05-27 | Insecure Execution-assigned Permissions | |||