Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument.
| Software | From | Fixed in |
|---|---|---|
| slrn_development_team / slrn | 0.9.6.3 | 0.9.6.3.x |
| slrn_development_team / slrn | 0.9.6.4 | 0.9.6.4.x |
| slrn_development_team / slrn | 0.9.6.2 | 0.9.6.2.x |