First published: Tue Nov 14 2000(Updated: )
Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gnome Esound | =0.2.19 | |
GNOME esound | =0.2.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0864 is classified as a local privilege escalation vulnerability.
To mitigate CVE-2000-0864, upgrade GNOME esound to version 0.2.20 or later.
Exploiting CVE-2000-0864 allows a local user to change permissions of arbitrary files and directories.
CVE-2000-0864 affects users of GNOME esound versions 0.2.19 and earlier.
CVE-2000-0864 requires local access, making it a local exploit rather than a remote vulnerability.