Security Advisory
CVE-2003-1167
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.