CVE
- Id
- 7165
- CVE No.
- CVE-2003-0337
- Status
- Candidate
- Description
- The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the LSF_ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF_SERVERDIR to point to a malicious lim program, which lsadmin then executes.
- Phase
- Assigned (20030522)
- Votes
- None (candidate not yet proposed)
- Comments