FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2003-1167

This CVE name corresponds to:

Entered Topic
2006-02-07 kpopup -- local root exploit and local denial of service

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2003-1167
Phase Assigned(20050504)

Description

misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.

References

Source Reference
BUGTRAQ 20031028 Local root vuln in kpopup
BID 8915
OSVDB 2742
SECUNIA 10105
XF kpopup-systemcall-execute-code(13540)