Sonata Local Arbitrary Command Excution Vulnerability

Users of Sonata, a voice conferencing switch from Voyant Technologies, may be vulnerable to a local compromise of root privileges.

Sonata comes with a program installed setuid root that will execute supplied arguments. As installed, it is exectuable by all users. As a result, host security can be readily compromised by a malicious local user.


