The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.
References
Link | Resource |
---|---|
http://www.debian.org/security/2004/dsa-509 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/10437 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16273 |
Configurations
History
No history.
Information
Published : 2004-12-06 05:00
Updated : 2024-02-04 16:31
NVD link : CVE-2004-0395
Mitre link : CVE-2004-0395
CVE.ORG link : CVE-2004-0395
JSON object : View
Products Affected
gatos
- gatos
CWE