Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-1226

Опубликовано: 06 апр. 2018
Источник: debian

Описание

The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
s3dfixed0.2.2-13package

Примечания

  • http://hmarco.org/bugs/CVE-2014-1226-s3dvt_0.2.2-root-shell.html

  • Additional patch hunk applied in 0.2.2-11 (experimental) only

  • Not running with elevated privileges in Debian packaging

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876.

CVSS3: 7.8
nvd
почти 8 лет назад

The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876.

CVSS3: 7.8
github
больше 3 лет назад

The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876.