4.6
CVSSv2

CVE-2001-1272

Published: 06/12/2001 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

wmtv 0.6.5 and previous versions does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.

Vulnerable Product Search on Vulmon Subscribe to Product

wliang wmtv

Vendor Advisories

Nicolas Boullis found a nasty security problem in the wmtv (a dockable video4linux TV player for windowmaker) package as distributed in Debian GNU/Linux 22 wmtv can optionally run a command if you double-click on the TV window This command can be specified using the -e command line option However, since wmtv is installed suid root, this command ...