The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876.
Name | Vendor | Start Version | End Version |
---|---|---|---|
S3dvt | S3dvt_project | * | 0.2.2 (including) |
S3d | Ubuntu | lucid | * |
S3d | Ubuntu | precise | * |
S3d | Ubuntu | saucy | * |
S3d | Ubuntu | upstream | * |