7.2
CVSSv2

CVE-2004-0395

Published: 06/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.

Vulnerable Product Search on Vulmon Subscribe to Product

gatos gatos .5

Vendor Advisories

Steve Kemp discovered a vulnerability in xatitv, one of the programs in the gatos package, which is used to display video with certain ATI video cards xatitv is installed setuid root in order to gain direct access to the video hardware It normally drops root privileges after successfully initializing itself However, if initialization fails due t ...