efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger.
| Software | From | Fixed in |
|---|---|---|
| efingerd / efingerd | 1.3 | 1.3.x |
| efingerd / efingerd | 1.6.1 | 1.6.1.x |