CVE Vulnerabilities

CVE-2003-0704

Published: Sep 17, 2003 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

KisMAC before 0.05d trusts user-supplied variables when chown’ing files or directories, which allows local users to gain privileges via the $DRIVER_KEXT environment variable in (1) viha_driver.sh, (2) macjack_load.sh, (3) airojack_load.sh, (4) setuid_enable.sh, (5) setuid_disable.sh, and using a similar technique for (6) viha_prep.sh and (7) viha_unprep.sh.

Affected Software

Name Vendor Start Version End Version
Kismac Kismac 0.05d 0.05d

References