|
|
| |
|
| |
xonix fails to drop privileges
| Package(s): | xonix |
CVE #(s): | CAN-2004-0157
|
| Created: | April 15, 2004 |
Updated: | April 21, 2004 |
| Description: |
Steve Kemp discovered a vulnerability in xonix, a game, where an
external program was invoked while retaining setgid privileges. A
local attacker could exploit this vulnerability to gain gid "games". |
| Alerts: |
|
( Log in to post comments)
|
|
|