Description
frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.
Exploits (1)
References (2)
Core 2
Core References
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/14711
Exploit, Vendor Advisory mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/409667
Scores
EPSS
0.0040
EPSS Percentile
60.7%
Details
Status
published
Products (1)
frox/frox
0.7.18
Published
Sep 07, 2005
Tracked Since
Feb 18, 2026