misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Debian_linux |
Debian |
4.0 (including) |
4.0 (including) |
References