The ndcfg command raises its privileges with the security subsystem (as opposed to being setuid), and has a buffer overlow in its command line processing. This could allow a malicious user to run code of their choice with raised privileges. View the full article at http://www.osforge.com/news/00842.html