tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a filename to the -S command-line option.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2011/1015 | vdb entry vendor advisory |
http://secunia.com/advisories/44081 | third party advisory vendor advisory |
http://secunia.com/advisories/44239 | third party advisory vendor advisory |
http://www.exploit-db.com/exploits/17147 | exploit |
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058452.html | vendor advisory |
http://www.securityfocus.com/bid/47283 | vdb entry |
http://www.debian.org/security/2011/dsa-2212 | vendor advisory |
http://www.vupen.com/english/advisories/2011/0897 | vdb entry vendor advisory |
http://www.vupen.com/english/advisories/2011/1002 | vdb entry vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058548.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058367.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/66693 | vdb entry |