CVE
- Id
- 2578
- CVE No.
- CVE-2000-1009
- Status
- Candidate
- Description
- dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.
- Phase
- Proposed (20001129)
- Votes
- ACCEPT(5) Baker, Cole, Frech, Mell, Renaud | NOOP(1) Christey
- Comments
- Christey> http://www.redhat.com/support/errata/RHSA-2000-100.html | ADDREF BUGTRAQ:20001103 Trustix Security Advisory - dump | http://archives.neohapsis.com/archives/bugtraq/2000-11/0026.html | Christey> CERT-VN:VU#153653 | URL:http://www.kb.cert.org/vuls/id/153653