1 results (0.003 seconds)

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges. artswrapper en aRts, cuando se ejecuta como root sobre linux 2.6.0 o versiones posteriores, no valida la variable setuid de retorno de la llamada a la función, lo que permite a usuarios locales ganar privilegios de root al provocar un fallo sobre setuid. • http://dot.kde.org/1150310128 http://mail.gnome.org/archives/beast/2006-December/msg00025.html http://secunia.com/advisories/20677 http://secunia.com/advisories/20786 http://secunia.com/advisories/20827 http://secunia.com/advisories/20868 http://secunia.com/advisories/20899 http://secunia.com/advisories/25032 http://secunia.com/advisories/25059 http://security.gentoo.org/glsa/glsa-200704-22.xml http://securitytracker.com/id?1016298 http://slackware.com/security/viewer.php? • CWE-273: Improper Check for Dropped Privileges •