CVE

Id
2578  
CVE No.
CVE-2000-1009  
Status
Candidate  
Description
dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.  
Phase
Proposed (20001129)  
Votes
ACCEPT(5) Baker, Cole, Frech, Mell, Renaud | NOOP(1) Christey  
Comments
Christey> http://www.redhat.com/support/errata/RHSA-2000-100.html | ADDREF BUGTRAQ:20001103 Trustix Security Advisory - dump | http://archives.neohapsis.com/archives/bugtraq/2000-11/0026.html | Christey> CERT-VN:VU#153653 | URL:http://www.kb.cert.org/vuls/id/153653