CVE
- Id
- 9278
- CVE No.
- CVE-2004-0850
- Status
- Candidate
- Description
- Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.
- Phase
- Assigned (20040913)
- Votes
- None (candidate not yet proposed)
- Comments