scponlyc in scponly 4.1 and earlier, when the operating system supports LD_PRELOAD mechanisms, allows local users to execute arbitrary code with root privileges by creating a chroot directory in their home directory, hard linking to a system setuid application, and using a modified LD_PRELOAD to modify expected function calls in the setuid application.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Scponly | Scponly | 3.1 (including) | 3.1 (including) |
Scponly | Scponly | 3.2 (including) | 3.2 (including) |
Scponly | Scponly | 3.3 (including) | 3.3 (including) |
Scponly | Scponly | 3.4 (including) | 3.4 (including) |
Scponly | Scponly | 3.6 (including) | 3.6 (including) |
Scponly | Scponly | 3.7 (including) | 3.7 (including) |
Scponly | Scponly | 3.8 (including) | 3.8 (including) |
Scponly | Scponly | 3.9 (including) | 3.9 (including) |
Scponly | Scponly | 3.11 (including) | 3.11 (including) |
Scponly | Scponly | 4.0 (including) | 4.0 (including) |
Scponly | Scponly | 4.1 (including) | 4.1 (including) |
Scponly | Ubuntu | dapper | * |
Scponly | Ubuntu | devel | * |
Scponly | Ubuntu | edgy | * |
Scponly | Ubuntu | feisty | * |