The pipeinitterminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "0.2.2-9",
"binary_name": "dotmcp"
},
{
"binary_version": "0.2.2-9",
"binary_name": "kism3d"
},
{
"binary_version": "0.2.2-9",
"binary_name": "libs3d-dev"
},
{
"binary_version": "0.2.2-9",
"binary_name": "libs3d2"
},
{
"binary_version": "0.2.2-9",
"binary_name": "libs3dw-dev"
},
{
"binary_version": "0.2.2-9",
"binary_name": "libs3dw2"
},
{
"binary_version": "0.2.2-9",
"binary_name": "meshs3d"
},
{
"binary_version": "0.2.2-9",
"binary_name": "s3d"
},
{
"binary_version": "0.2.2-9",
"binary_name": "s3d-data"
},
{
"binary_version": "0.2.2-9",
"binary_name": "s3d-dbg"
},
{
"binary_version": "0.2.2-9",
"binary_name": "s3d-doc"
},
{
"binary_version": "0.2.2-9",
"binary_name": "s3dfm"
},
{
"binary_version": "0.2.2-9",
"binary_name": "s3dosm"
},
{
"binary_version": "0.2.2-9",
"binary_name": "s3dvt"
},
{
"binary_version": "0.2.2-9",
"binary_name": "s3dx11gate"
}
]
}