The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.
Link | Tags |
---|---|
http://www.novell.com/linux/security/advisories/suse_security_announce_50.html | vendor advisory |
http://www.securityfocus.com/bid/1206 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2000-05/0172.html | mailing list |