It has been alleged that it is possible for local attackers to take advantage of format string vulnerabilities in kpopup, which is installed setuid root by default. According to the report, kpopup does not correctly handle format strings when passed to the program as arguments. This may result in local privilege elevation.
It has been alleged that it is possible for local attackers to take advantage of format string vulnerabilities in kpopup, which is installed setuid root by default. According to the report, kpopup does not correctly handle format strings when passed to the program as arguments. This may result in local privilege elevation.