share/ma/keys_for_user in Monkeysphere 0.31 and 0.32 allows local users to execute arbitrary code via unknown manipulations related to the "monkeysphere-authentication keys-for-user" command.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
http://web.monkeysphere.info/news/CVE-2010-4096/ | |
http://secunia.com/advisories/42067 | third party advisory |
https://lists.riseup.net/www/arc/monkeysphere/2010-10/msg00066.html | mailing list |