CVE-2013-6876 - s3dvt root shell

Hector Marco Gisbert, Ismael Ripoll

Research output: Other contribution

Abstract

A bug in s3dvt for versions prior to 0.2.2 has been found. The bug is caused by not checking the return values of setuid() and getuid() calls. The process must not continue its normal execution when any of these calls fail (return an error) to drop privileges.
LanguageEnglish
TypeCVE-2013-6876
Publisherhttp://hmarco.org
StatePublished - 25 Mar 2014

Cite this

@misc{359920e17e354f0d8d935d1f45f60a63,
title = "CVE-2013-6876 - s3dvt root shell",
abstract = "A bug in s3dvt for versions prior to 0.2.2 has been found. The bug is caused by not checking the return values of setuid() and getuid() calls. The process must not continue its normal execution when any of these calls fail (return an error) to drop privileges.",
author = "{Marco Gisbert}, Hector and Ismael Ripoll",
year = "2014",
month = "3",
day = "25",
language = "English",
publisher = "http://hmarco.org",
type = "Other",

}

CVE-2013-6876 - s3dvt root shell. / Marco Gisbert, Hector; Ripoll, Ismael.

http://hmarco.org. 2014, CVE-2013-6876.

Research output: Other contribution

TY - GEN

T1 - CVE-2013-6876 - s3dvt root shell

AU - Marco Gisbert,Hector

AU - Ripoll,Ismael

PY - 2014/3/25

Y1 - 2014/3/25

N2 - A bug in s3dvt for versions prior to 0.2.2 has been found. The bug is caused by not checking the return values of setuid() and getuid() calls. The process must not continue its normal execution when any of these calls fail (return an error) to drop privileges.

AB - A bug in s3dvt for versions prior to 0.2.2 has been found. The bug is caused by not checking the return values of setuid() and getuid() calls. The process must not continue its normal execution when any of these calls fail (return an error) to drop privileges.

M3 - Other contribution

PB - http://hmarco.org

ER -