SPE: Insecure file permissions SPE files are installed with world-writeable permissions, potentially leading to privilege escalation. spe October 15, 2005 May 22, 2006: 02 108538 local 0.7.5c-r1 0.5.1f-r1 0.7.5c-r1

SPE is a cross-platform Python Integrated Development Environment (IDE).

It was reported that due to an oversight all SPE's files are set as world-writeable.

A local attacker could modify the executable files, causing arbitrary code to be executed with the permissions of the user running SPE.

There is no known workaround at this time.

All SPE users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose dev-util/spe
CVE-2005-3291 jaervosz adir koon