<title>aRts: Privilege escalation</title>
The artswrapper part of aRts allows local users to execute arbitrary code
with elevated privileges.
<product type="ebuild">aRts</product>
<announced>June 22, 2006</announced>
<revised>June 22, 2006: 01</revised>
<package name="kde-base/arts" auto="yes" arch="*">
<unaffected range="ge">3.5.2-r1</unaffected>
<unaffected range="rge">3.4.3-r1</unaffected>
<vulnerable range="lt">3.5.2-r1</vulnerable>
aRts is a real time modular system for synthesizing audio used by KDE.
artswrapper is a helper application used to start the aRts daemon.
artswrapper fails to properly check whether it can drop privileges
accordingly if setuid() fails due to a user exceeding assigned resource
<impact type="high">
Local attackers could exploit this vulnerability to execute arbitrary
code with elevated privileges. Note that the aRts package provided by
Gentoo is only vulnerable if the artswrappersuid USE-flag is enabled.
There is no known workaround at this time.
All aRts users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose kde-base/arts</code>
<uri link="">CVE-2006-2916</uri>
