SplitVT: Privilege escalation A vulnerability in SplitVT may allow local users to gain escalated privileges. splitvt 2008-03-03 2008-03-03 211240 local 1.6.6-r1 1.6.6-r1

SplitVT is a program for splitting terminals into two shells.

Mike Ashton reported that SplitVT does not drop group privileges before executing the xprop utility.

A local attacker could exploit this vulnerability to gain the "utmp" group privileges.

There is no known workaround at this time.

All SplitVT users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-misc/splitvt-1.6.6-r1"
CVE-2008-0162 jaervosz jaervosz p-y