|
|

CVE Reference: CVE-2005-3149 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2005-3149 |
|
|
Description: Uim 0.4.x before 0.4.9.1 and 0.5.0 and earlier does not properly handle the LIBUIM_VANILLA environment variable when a suid or sgid application is linked to libuim, such as immodule for Qt, which allows local users to gain privileges. |
|
|
CVE Status: Candidate |
|
|
References: ST 1015002 SAID Secunia Advisory: SA17043 Secunia Advisory: SA17058 Secunia Advisory: SA17572 MLIST http://lists.freedesktop.org/pipermail/uim/2005-September/001347.html http://lists.freedesktop.org/pipermail/uim/2005-September/001346.html GENTOO http://www.gentoo.org/security/en/glsa/glsa-200510-03.xml DEBIAN http://www.debian.org/security/2005/dsa-895 CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=331620 BID 15007 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |