CVE

Id
4128  
CVE No.
CVE-2001-1324  
Status
Candidate  
Description
cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.  
Phase
Modified (20050526)  
Votes
ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  
Comments
CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:idtools-cmvlogin-root-privileges(9987)