Ktsuss Project Ktsuss vulnerabilities
2 known vulnerabilities affecting ktsuss_project/ktsuss.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2011-2921P2CRITICALCVSS 9.8PoC≤ 1.42019-11-19
CVE-2011-2921 [CRITICAL] CWE-273 CVE-2011-2921: ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executin
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
nvd
CVE-2011-2922P3HIGHCVSS 7.8≤ 1.42019-11-19
CVE-2011-2922 [HIGH] CWE-20 CVE-2011-2922: ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attack
ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GTK_MODULES" environment variable to possibly execute arbitrary code.
nvd