LWN.net Logo

xonix fails to drop privileges

Package(s):xonix CVE #(s):CAN-2004-0157
Created:April 15, 2004 Updated:April 21, 2004
Description: Steve Kemp discovered a vulnerability in xonix, a game, where an external program was invoked while retaining setgid privileges. A local attacker could exploit this vulnerability to gain gid "games".
Alerts:
Debian DSA-484-1 2004-04-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds