PT-2003-2119 · Kde · Kpopup

Published

2003-12-31

·

Updated

2017-07-11

·

CVE-2003-1167

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions KPopup version 0.9.1
Description The issue is related to the execution of the killall command in KPopup, where it trusts the PATH variable. This allows local users to potentially elevate their privileges by modifying the PATH variable to point to a malicious killall program.
Recommendations For KPopup version 0.9.1, consider restricting access to the PATH variable or using an absolute path when executing the killall command to prevent exploitation. As a temporary workaround, avoid using the killall command in KPopup until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1167

Affected Products

Kpopup