Security Advisory

CVE-2003-1358

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-10-17 01:00:00
Last updated 2024-08-08 02:28:03
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.