CVE-2004-0850

Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.
Configurations

Configuration 1 (hide)

cpe:2.3:a:joerg_schilling:star_tape_archiver:1.5_a45:*:*:*:*:*:*:*

History

No history.

Information

Published : 2004-12-23 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2004-0850

Mitre link : CVE-2004-0850

CVE.ORG link : CVE-2004-0850


JSON object : View

Products Affected

joerg_schilling

  • star_tape_archiver