CVE-2021-26936

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
10/02/2021
Last modified:
16/02/2021

Description

The replay-sorcery program in ReplaySorcery 0.4.0 through 0.5.0, when using the default setuid-root configuration, allows a local attacker to escalate privileges to root by specifying video output paths in privileged locations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:replaysorcery_project:replaysorcery:*:*:*:*:*:*:*:* 0.4.0 (including) 0.5.0 (including)