vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/14170 | vdb entry |
http://www.securityfocus.com/bid/9381 | vdb entry vendor advisory |
http://www.debian.org/security/2004/dsa-418 | patch vendor advisory |