rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/advisories/4960 | vendor advisory |
http://www.securityfocus.com/archive/1/324381 | mailing list |
http://securityreason.com/securityalert/3236 | third party advisory |
http://www.securityfocus.com/bid/6837 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11312 | vdb entry |