PT-2014-3642 · Super · Super

John Lightsey

·

Published

2014-04-30

·

Updated

2014-07-18

·

CVE-2014-0470

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Super version 3.30.0
Description The issue allows local users to gain privileges via unspecified vectors, related to an RLIMIT NPROC attack, due to the setuid function's return value not being checked when the -F flag is set in the super.c file.
Recommendations For Super version 3.30.0, consider updating to a newer version that includes a fix for this issue, as the current version does not properly check the return value of the setuid function, potentially allowing privilege escalation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0470
DSA-2917-1

Affected Products

Super