PT-2008-2728 · Unknown · Net Activity Viewer
Publicado
2008-03-04
·
Atualizado
2008-09-05
·
CVE-2008-1132
CVSS v2.0
4.7
Média
| Vetor | AV:L/AC:M/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Net Activity Viewer version 0.2.1
Description
The issue allows local users with Net Activity Viewer privileges to execute arbitrary code via a malicious gksu program, which is invoked during the Restart As Root action. This is due to an untrusted search path vulnerability in the src/mainwindow.c file.
Recommendations
For Net Activity Viewer version 0.2.1, consider restricting the use of the Restart As Root action until a patch is available, and ensure that all gksu programs invoked are from trusted sources.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Net Activity Viewer