RSS   Vulnerabilities for 'Star tape archiver'   RSS

2004-12-23
 
CVE-2004-0850

 

 
Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.

 


Copyright 2024, cxsecurity.com

 

Back to Top