LWN.net Logo

fvwm: fvwm-menu-directory command injection

Package(s):fvwm CVE #(s):CVE-2006-5969
Created:November 24, 2006 Updated:November 29, 2006
Description: Tavis Ormandy of the Gentoo Linux Security Audit Team discovered that fvwm-menu-directory does not sufficiently sanitize directory names prior to generating menus. A local attacker who can convince an fvwm-menu-directory user to browse a directory they control could cause fvwm commands to be executed with the privileges of the fvwm user. Fvwm commands can be used to execute arbitrary shell commands.
Alerts:
Gentoo 200611-17 2006-11-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds