April 17, 2001

BubbleMon 1.31 vulnerability in FreeBSD

Author: JT Smith

From Net-security.org: Users can execute programs/shellscript by clicking on the
bubblemon app. bubblemon is installed sgid kmem on
FreeBSD and does not drop its egid before executing

Versions affected include all versions of BubbleMon up to 1.32 installed on FreeBSD.


