|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
suGuard contains a flaw that allows any local user to gain root privileges. The flaw is due to suGuard's main application running the 'ps' program based on the user's PATH environment. When it calls the program it does so with root privileges, but does not verify the program it is running. A malicious local attacker can put a specially crafted 'ps' command in their path and have suGuard run it instead.
|
|
Classification |
Unknown or Incomplete
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
suGuard
 |
1.0 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|