The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and previous versions. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
s3dvt project s3dvt |