vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.
References
| Link | Resource |
|---|---|
| http://www.debian.org/security/2004/dsa-418 | Patch Vendor Advisory |
| http://www.securityfocus.com/bid/9381 | Vendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/14170 |
Configurations
Information
Published : 2004-02-02 21:00
Updated : 2017-10-09 18:30
NVD link : CVE-2004-0015
Mitre link : CVE-2004-0015
JSON object : View
CWE
Products Affected
vbox3
- vbox3


