efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically nobody), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Efingerd | Efingerd | 1.3 (including) | 1.3 (including) |
Efingerd | Efingerd | 1.6.1 (including) | 1.6.1 (including) |