BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bubblemon | Timecop | 1.0 (including) | 1.0 (including) |
Bubblemon | Timecop | 1.0pl1 (including) | 1.0pl1 (including) |
Bubblemon | Timecop | 1.0pl2 (including) | 1.0pl2 (including) |
Bubblemon | Timecop | 1.0pl3 (including) | 1.0pl3 (including) |
Bubblemon | Timecop | 1.0pl4 (including) | 1.0pl4 (including) |
Bubblemon | Timecop | 1.0pl6 (including) | 1.0pl6 (including) |
Bubblemon | Timecop | 1.0pl7 (including) | 1.0pl7 (including) |
Bubblemon | Timecop | 1.0pl8 (including) | 1.0pl8 (including) |
Bubblemon | Timecop | 1.0pl9 (including) | 1.0pl9 (including) |
Bubblemon | Timecop | 1.1 (including) | 1.1 (including) |
Bubblemon | Timecop | 1.1test1 (including) | 1.1test1 (including) |
Bubblemon | Timecop | 1.1test2 (including) | 1.1test2 (including) |
Bubblemon | Timecop | 1.1test3 (including) | 1.1test3 (including) |
Bubblemon | Timecop | 1.1test4 (including) | 1.1test4 (including) |
Bubblemon | Timecop | 1.1test5 (including) | 1.1test5 (including) |
Bubblemon | Timecop | 1.1test6 (including) | 1.1test6 (including) |
Bubblemon | Timecop | 1.1test7 (including) | 1.1test7 (including) |
Bubblemon | Timecop | 1.2 (including) | 1.2 (including) |
Bubblemon | Timecop | 1.2test1 (including) | 1.2test1 (including) |
Bubblemon | Timecop | 1.3 (including) | 1.3 (including) |
Bubblemon | Timecop | 1.21 (including) | 1.21 (including) |
Bubblemon | Timecop | 1.21test1 (including) | 1.21test1 (including) |
Bubblemon | Timecop | 1.22 (including) | 1.22 (including) |
Bubblemon | Timecop | 1.23 (including) | 1.23 (including) |
Bubblemon | Timecop | 1.31 (including) | 1.31 (including) |