SplitVT 'xprop' Local Privilege Escalation Vulnerability
BID:27936
Info
SplitVT 'xprop' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 27936 |
| Class: | Design Error |
| CVE: |
CVE-2008-0162 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 21 2008 12:00AM |
| Updated: | Mar 03 2008 10:12PM |
| Credit: | Mike Ashton is credited with the discovery of this vulnerability. |
| Vulnerable: |
Sam Lantinga splitvt 1.6.6 Sam Lantinga splitvt 1.6.5 Sam Lantinga splitvt 1.6.4 Sam Lantinga splitvt 1.6.3 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
SplitVT 'xprop' Local Privilege Escalation Vulnerability
SplitVT is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to gain group 'utmp' privileges on affected computers.
SplitVT is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to gain group 'utmp' privileges on affected computers.
Exploit / POC
SplitVT 'xprop' Local Privilege Escalation Vulnerability
No specific exploit is required. An attacker with local interactive access to the affected computer can exploit this issue.
No specific exploit is required. An attacker with local interactive access to the affected computer can exploit this issue.
Solution / Fix
SplitVT 'xprop' Local Privilege Escalation Vulnerability
Solution:
An advisory and updates are available to address this issue. Please see the references for more information.
Solution:
An advisory and updates are available to address this issue. Please see the references for more information.
References
SplitVT 'xprop' Local Privilege Escalation Vulnerability
References:
References:
- splitvt Homepage (Sam Lantinga)