Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

S.u.S.E. 6.0 xtvscreen Vulnerability

xtvscreen is a screen capture utility shipped with SuSE Linux 6. It's supposed to create files in it's working directory to store the captured images. Unfortunately, it will also follow symlinks. Since xtvscreen is suid root by default, it will overwrite any file on the system.







 

Privacy Statement
Copyright 2009, SecurityFocus