CVE-2011-1496 Information
Description
tmux 1.3 and 1.4 does not properly drop group privileges which allows local users to gain utmp group privileges via a filename to the -S command-line option.
Reference
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058367.html http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058452.html http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058548.html http://secunia.com/advisories/44081 http://secunia.com/advisories/44239 http://www.debian.org/security/2011/dsa-2212 http://www.exploit-db.com/exploits/17147 http://www.securityfocus.com/bid/47283 http://www.vupen.com/english/advisories/2011/0897 http://www.vupen.com/english/advisories/2011/1002 http://www.vupen.com/english/advisories/2011/1015 https://exchange.xforce.ibmcloud.com/vulnerabilities/66693
Share on: