Sign in
CVE-2003-1474
CVE-2003-1474
Description
slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris.
Impact
CVSS v2 : 7.2 HIGH
Type
CWE-264
Attack Vector
CVSSv2 Vector : AV:L/AC:L/Au:N/C:C/I:C/A:C
Quick links
CVE
,
NVD
,
CERT
,
Metasploit
,
Exploit-db
,
Fulldisc
,
Bugtraq
,
Microsoft
,
Red Hat
,
Debian
, GitHub
code
/
issues
,
Google
References
http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-05/0122.html
http://www.iss.net/security_center/static/11979.php
http://www.securityfocus.com/archive/1/321001
FAQ
Terms of service
Privacy policy