Users of Sonata, a voice conferencing switch from Voyant Technologies, may be vulnerable to a local compromise of root privileges. Sonata comes with a program installed setuid root that will execute supplied arguments. As installed, it is exectuable by all users. As a result, host security can be readily compromised by a malicious local user.
Users of Sonata, a voice conferencing switch from Voyant Technologies, may be vulnerable to a local compromise of root privileges. Sonata comes with a program installed setuid root that will execute supplied arguments. As installed, it is exectuable by all users. As a result, host security can be readily compromised by a malicious local user.