abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/354 | exploit vdb entry patch vendor advisory |
http://marc.info/?l=bugtraq&m=87602167418994&w=2 | mailing list |