4.6
CVSSv2

CVE-1999-0820

Published: 01/12/1999 Updated: 09/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 3.3

Exploits

source: wwwsecurityfocuscom/bid/780/info Seyon uses relative pathnames to spawn two other programs which it requires It is possible to exploit this vulnerability to obtain the priviliges which seyon runs with It is installed (by default) setgid dialer on FreeBSD and root on Irix bash-203$ uname -a; id; ls -la `which seyon` FreeBSD 3 ...