Note:
This project will be discontinued after December 13, 2021. [more]
2014-04-30
super.c in Super 3.30.0 does not check the return value of the setuid function when the -F flag is set, which allows local users to gain privileges via unspecified vectors, aka an RLIMIT_NPROC attack.
Products | Super |
Type | Permissions, Privileges, and Access Controls (CWE-264) |
First patch | - None (likely due to unavailable code) |
Links |
• http://www.debian.org/security/2014/dsa-2917
• http://www.openwall.com/lists/oss-security/2014/04/28/6 |