Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This vulnerability has a 0.47% probability of being exploited in the next 30 days, ranking higher than 38% of all scored CVEs.