CVE Vulnerabilities

CVE-2008-0162

Published: Feb 22, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.

Affected Software

NameVendorStart VersionEnd Version
Debian_linuxDebian4.0 (including)4.0 (including)
SplitvtUbuntudapper*
SplitvtUbuntudevel*
SplitvtUbuntuedgy*
SplitvtUbuntufeisty*
SplitvtUbuntugutsy*
SplitvtUbuntuhardy*
SplitvtUbuntuintrepid*
SplitvtUbuntujaunty*

References