The init scripts in Search for Extraterrestrial Intelligence (SETI) project 3.08-r3 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.
Link | Tags |
---|---|
http://www.gentoo.org/security/en/glsa/glsa-200411-26.xml | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18149 | vdb entry |