20000516 kscd vulnerabilitymailing list
http://archives.neohapsis.com/archives/bugtraq/2000-05/0172.html CVE-2000-0393
KDE 1.1/1.1.1/1.2/2.0 kscd - SHELL Environmental Variable
Record summary
CVE-2000-0393 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBKDE 1.1/1.1.1/1.2/2.0 kscd - SHELL Environmental VariableExploitDB exploitby SebastianNot analyzed1 file
References
420000529 kmulti <= 1.1.2Vendor advisory
http://www.novell.com/linux/security/advisories/suse_security_announce_50.html 1206vdb entry
http://www.securityfocus.com/bid/1206 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0393