Improper Privilege Dropping in frox 0.7.18 Allows Local File Read

Improper Privilege Dropping in frox 0.7.18 Allows Local File Read

CVE-2005-2807 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.

Learn more about our User Device Pen Test.