|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
The FVWM window manager contains a flaw that may allow a malicious user to prepare a script containing malicious commands for execution by another user. The issue is triggered when FVWM opens the directory in which the script is placed. It is possible that the flaw may allow execution of resulting in a loss of confidentiality and integrity.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 2.5.9, 2.4.18 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
FVWM
 |
2.4.17 |
2.5.8 |
|
|
|
|
Credit |
- - auto22238
hushmail.com -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|