Candidate: CVE-2014-1226 PublicDate: 2018-04-06 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1226 http://hmarco.org/bugs/CVE-2014-1226-s3dvt_0.2.2-root-shell.html http://www.openwall.com/lists/oss-security/2014/06/03/13 Description: The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876. Ubuntu-Description: Notes: seth-arnold> Debian notes: Not running with elevated privileges in Debian packaging seth-arnold> automated triage tools suggested debian had released a fix, but I did not verify sbeattie> debian fix in 0.2.2-9 is slightly different from Hector's patch Bugs: Priority: medium Discovered-by: Hector Marco Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_s3d: other: http://hmarco.org/bugs/patches/s3dvt-fix-setuid-pipe-terminal.patch upstream_s3d: needed lucid_s3d: ignored (reached end-of-life) precise_s3d: ignored (reached end-of-life) precise/esm_s3d: DNE (precise was needed) saucy_s3d: ignored (reached end-of-life) trusty_s3d: not-affected (0.2.2-9) trusty/esm_s3d: DNE (trusty was not-affected [0.2.2-9]) utopic_s3d: not-affected (0.2.2-9) vivid_s3d: not-affected (0.2.2-9) vivid/stable-phone-overlay_s3d: DNE vivid/ubuntu-core_s3d: DNE wily_s3d: not-affected (0.2.2-9) xenial_s3d: not-affected (0.2.2-9) yakkety_s3d: not-affected (0.2.2-9) zesty_s3d: not-affected (0.2.2-9) devel_s3d: not-affected (0.2.2-9)