rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2003-12-30 21:00
Updated : 2017-07-28 18:29
NVD link : CVE-2003-1358
Mitre link : CVE-2003-1358
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
hp
- hp-ux