xsok 1.02 does not properly drop privileges before finding and executing the "gunzip" program, which allows local users to execute arbitrary commands.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.debian.org/security/2003/dsa-405 | Patch Vendor Advisory | 
| http://www.securityfocus.com/bid/9321 | Patch Vendor Advisory | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/14098 | 
Configurations
                    Information
                Published : 2004-02-02 21:00
Updated : 2017-07-10 18:29
NVD link : CVE-2003-0949
Mitre link : CVE-2003-0949
JSON object : View
CWE
                Products Affected
                michael_bischoff
- xsok
 


