CVE-2005-0070

NameCVE-2005-0070
DescriptionSynaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbitrary files.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-681-1

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
synaesthesiasourcewoody2.1-2.1woody3DSA-681-1
synaesthesiasource(unstable)2.1-3

Notes

does not apply for sarge, program is not setuid anymore

Search for package or bug name: Reporting problems