Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe is NOT designed to run setuid-root. Therefore this identifier applies only to those configurations and installations under which pppoe is run setuid root despite the developers warnings.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pppoe | Roaring_penguin | 3.0 (including) | 3.0 (including) |
Pppoe | Roaring_penguin | 3.3 (including) | 3.3 (including) |
Pppoe | Roaring_penguin | 3.5 (including) | 3.5 (including) |
Rp-pppoe | Ubuntu | dapper | * |
Rp-pppoe | Ubuntu | devel | * |
Rp-pppoe | Ubuntu | edgy | * |
Rp-pppoe | Ubuntu | feisty | * |