CVE-2004-0395

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/12/2004
Last modified:
03/04/2025

Description

The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gatos:gatos:.5:*:*:*:*:*:*:*