Executive brief
A security vulnerability exists in the Common Desktop Environment (CDE), a graphical user interface used on many older Unix-based operating systems. A specific utility within this environment, dtappgather, contains a flaw that allows a local user to gain unauthorized administrative privileges or crash the system. This could lead to a total loss of system confidentiality and control by an unauthorized individual.
Technical details
A vulnerability exists in the dtappgather utility within the Common Desktop Environment (CDE). The flaw allows a local attacker to perform an escalation of privilege or cause a denial of service. The root cause is typically associated with insecure file handling or environment variable processing by the setuid-root dtappgather binary. An attacker with local access can exploit this to gain root-level permissions or disrupt system availability. Patches were historically released by vendors such as Sun Microsystems and HP to address this issue.
Affected products
- Open Group Common Desktop Environment (CDE)
Timeline
- 1998-01-21: disclosed: Initial publication date