CVE-2000-0393 Information

Description

The KDE kscd program does not drop privileges when executing a program specified in a user’s SHELL environmental variable which allows the user to gain privileges by specifying an alternate program to execute.

Reference

http://archives.neohapsis.com/archives/bugtraq/2000-05/0172.html http://www.novell.com/linux/security/advisories/suse_security_announce_50.html http://www.securityfocus.com/bid/1206

Share on: