GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/2165 | patch vendor advisory exploit vdb entry third party advisory |
http://archives.neohapsis.com/archives/bugtraq/2000-12/0498.html | mailing list exploit |
http://archives.neohapsis.com/archives/bugtraq/2001-01/0027.html | third party advisory mailing list |
http://www.gtk.org/setuid.html | third party advisory |