CVE
- Id
- 4128
- CVE No.
- CVE-2001-1324
- Status
- Candidate
- Description
- cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.
- Phase
- Modified (20050526)
- Votes
- ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall
- Comments
- CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:idtools-cmvlogin-root-privileges(9987)