BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/2609 | vdb entry patch vendor advisory |
http://marc.info/?l=bugtraq&m=98744422105430&w=2 | mailing list |