Info On The Disclosure Of The Wicd 0Day
We slipped up in wanting to show off how a student found an exploit in class (posted here). The truth was it was a critical exploit to Wicd, but a very minor vulnerability, if that, for Backtrack. What has been missed in all of this is that it is a real priv escalation 0day for distros that are used in multi user deployments, such as Arch, Debian, etc. Being in the security industry, the vuln was discovered on the BT5 distribution and unfortunately that was where we focused instead of placing the focus on wicd....