ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local malicious user to escalate privileges to root and use the "GTK_MODULES" environment variable to possibly execute arbitrary code.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ktsuss project ktsuss |