Security Advisory

CVE-2003-0171

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2003-04-15 04:00:00
Last updated 2024-08-08 01:43:36
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.