LWN.net Logo

synaesthesia - insecure file creation

Package(s):synaesthesia CVE #(s):CAN-2004-0160
Created:February 23, 2004 Updated:February 25, 2004
Description: During an audit, Ulf Harnhammar discovered a vulnerability in synaesthesia, a program which represents sounds visually. synaesthesia created its configuration file while holding root privileges, allowing a local user to create files owned by root and writable by the user's primary group. This type of vulnerability can usually be easily exploited to execute arbitrary code with root privileges by various means.
Alerts:
Debian DSA-446-1 2004-02-21

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds