|
Roxio Toast DejaVu Component PATH Variable Local Privilege Escalation Vulnerability
Roxio Toast is prone to a local privilege-escalation vulnerability because it fails to properly sanitize user-supplied input. As a result, local users may set their own search path for external applications that are called by setuid programs that are included in Roxio Toast. This issue allows local attackers to gain superuser privileges, resulting in a complete compromise of affected computers. This issue affects the DejaVu component that is installed by default in a standard installation of the vulnerable application. DejaVu is a third-party component that is maintained by Propaganda Productions. Roxio Toast version 7 Titanium includes the vulnerable component; other versions may also be affected. |
|
Privacy Statement |