4.6
CVSSv2

CVE-2011-1496

Published: 18/04/2011 Updated: 17/08/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a filename to the -S command-line option.

Vulnerable Product Search on Vulmon Subscribe to Product

nicholas marriott tmux 1.3

nicholas marriott tmux 1.4

Exploits

--------------------------------------- | Team ph0x90bic proudly presents | | tmux -S 13/14 local utmp exploit | --------------------------------------- # Exploit Title: tmux '-S' Option Incorrect SetGID Local Privilege Escalation Vulnerability # Date: 11042011 # Author: ph0x90bic # Software Link: tmuxsourceforgenet/ # Version: 1 ...
tmux versions 13 and 14 suffer from a -S option incorrect setgid local privilege escalation vulnerability ...