CVE

Id
3895  
CVE No.
CVE-2001-1091  
Status
Candidate  
Description
The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.  
Phase
Proposed (20020315)  
Votes
ACCEPT(6) Armstrong, Baker, Cole, Frech, Green, Ziese | NOOP(2) Foat, Wall  
Comments