|
Multiple Unix flavors that install the 'empire' game contain a flaw that may allow a local user to gain privileges. The issue is due to the program not dropping SGID privileges when invoking commands. This can be used to execute a sub-process with the same privileges as the game, allowing any command to be run with the same group ID.
|