slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/321001 | mailing list |
http://www.iss.net/security_center/static/11979.php | vdb entry |
http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-05/0122.html | mailing list |