Total vulnerabilities in the database
rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.
Software | From | Fixed in |
---|---|---|
bsdi / bsd_os | 4.0.1 | 4.0.1.x |
bsdi / bsd_os | 3.1 | 3.1.x |
bsdi / bsd_os | 3.0 | 3.0.x |
bsdi / bsd_os | 4.0 | 4.0.x |