PT-2004-1911 · Star · Star
Published
2004-09-24
·
Updated
2017-07-11
·
CVE-2004-0850
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Star versions prior to 1.5 alpha46
Description:
The issue allows local users to potentially gain privileges by modifying the RSH environment variable to reference a malicious program, due to the software not dropping the effective user ID (euid) before calling external programs.
Recommendations:
For versions prior to 1.5 alpha46, consider dropping the effective user ID (euid) before calling external programs to prevent privilege escalation. As a temporary workaround, restrict access to modifying the RSH environment variable to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Star