pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate "cp" program.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html | mailing list exploit vendor advisory |
http://www.osvdb.org/1501 | vdb entry |
http://www.securityfocus.com/bid/1563 | exploit vdb entry patch vendor advisory |