CVE-2003-1474

slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freebsd:slashem-tty:0.0.6e.4f.8:*:*:*:*:*:*:*

History

20 Nov 2024, 23:47

Type Values Removed Values Added
References () http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-05/0122.html - () http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-05/0122.html -
References () http://www.iss.net/security_center/static/11979.php - () http://www.iss.net/security_center/static/11979.php -
References () http://www.securityfocus.com/archive/1/321001 - () http://www.securityfocus.com/archive/1/321001 -

Information

Published : 2003-12-31 05:00

Updated : 2024-11-20 23:47


NVD link : CVE-2003-1474

Mitre link : CVE-2003-1474

CVE.ORG link : CVE-2003-1474


JSON object : View

Products Affected

freebsd

  • slashem-tty
CWE
CWE-264

Permissions, Privileges, and Access Controls