CVE Vulnerabilities

CVE-2004-0395

Published: Dec 06, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.

Affected Software

Name Vendor Start Version End Version
Gatos Gatos .5 (including) .5 (including)
Gatos Ubuntu dapper *
Gatos Ubuntu devel *
Gatos Ubuntu edgy *
Gatos Ubuntu feisty *

References