Family: Debian Local Security Checks --> Category: infos
[DSA092] DSA-092-1 wmtv Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
Nicolas Boullis found a nasty security problem in the wmtv (a
dockable video4linux TV player for windowmaker) package as
distributed in Debian GNU/Linux 2.2.
wmtv can optionally run a command if you double-click on the TV
window. This command can be specified using the -e command line
option. However, since wmtv is installed suid root, this command
was also run as root, which gives local users a very simple way
to get root access.
This has been fixed in version 0.6.5-2potato1 by dropping root
rights before executing the command. We recommend that you
upgrade your wmtv package immediately.
Solution : http://www.debian.org/security/2001/dsa-092
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.