xsok 1.02 does not properly drop privileges before finding and executing the gunzip program, which allows local users to execute arbitrary commands.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xsok | Michael_bischoff | 1.02 (including) | 1.02 (including) |
Xsok | Ubuntu | dapper | * |
Xsok | Ubuntu | devel | * |
Xsok | Ubuntu | edgy | * |
Xsok | Ubuntu | feisty | * |