Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Gatos xatitv Missing Configuration File Privilege Escalation Vulnerability

The gatos xatitv utility is prone to a local privilege escalation vulnerability.

This issue may occur when the utility, which is installed setuid root, fails to drop privileges due to a missing configuration file. Unsanitized user-supplied environment variables may then be exploited to escalate privileges.

It is noted that the software ships with a default configuration file, so exploitation would require that the file was removed at some point.







 

Privacy Statement
Copyright 2009, SecurityFocus