CVE-2000-0393
KDE kscd - Privilege Escalation via SHELL Environment Variable
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-0393. PoCs published by Sebastian.
AI-analyzed exploit summary The exploit describes a vulnerability in kscd (KDE CD player) shipped with some Linux distributions (e.g., S.u.S.E. 6.4) where the 'SHELL' environment variable is used to execute a browser, allowing an attacker to obtain a sgid 'disk' shell and potentially escalate privileges to root by modifying disk attributes.
Description
The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.
Exploits (1)
The exploit describes a vulnerability in kscd (KDE CD player) shipped with some Linux distributions (e.g., S.u.S.E. 6.4) where the 'SHELL' environment variable is used to execute a browser, allowing an attacker to obtain a sgid 'disk' shell and potentially escalate privileges to root by modifying disk attributes.