RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of ownership.
{
"binaries": [
{
"binary_version": "1.18+dfsg-1",
"binary_name": "librenderdoc"
},
{
"binary_version": "1.18+dfsg-1",
"binary_name": "librenderdoc-dev"
},
{
"binary_version": "1.18+dfsg-1",
"binary_name": "python3-renderdoc"
},
{
"binary_version": "1.18+dfsg-1",
"binary_name": "qrenderdoc"
},
{
"binary_version": "1.18+dfsg-1",
"binary_name": "renderdoc"
},
{
"binary_version": "1.18+dfsg-1",
"binary_name": "renderdoccmd"
}
]
}