serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/2111 | vdb entry |
http://www.securityfocus.com/archive/1/930 | mailing list exploit vendor advisory |
http://www.securityfocus.com/bid/464 | exploit vdb entry patch vendor advisory |