Security Advisory

CVE-2003-0337

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2003-05-23 04:00:00
Last updated 2024-08-08 01:50:47
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the LSF_ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF_SERVERDIR to point to a malicious lim program, which lsadmin then executes.