rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/147120 | mailing list exploit vendor advisory |
http://www.securityfocus.com/bid/2009 | exploit vdb entry vendor advisory |