CVE

Id
9278  
CVE No.
CVE-2004-0850  
Status
Candidate  
Description
Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.  
Phase
Assigned (20040913)  
Votes
None (candidate not yet proposed)  
Comments