2.1
CVSSv2

CVE-2005-0072

Published: 24/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

zhcon prior to 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

ejoy and hu yong zhcon 0.2

Vendor Advisories

Erik Sjölund discovered that zhcon, a fast console CJK system using the Linux framebuffer, accesses a user-controlled configuration file with elevated privileges Thus, it is possible to read arbitrary files For the stable distribution (woody) this problem has been fixed in version 02-4woody3 For the unstable distribution (sid) this problem wil ...