7.2
CVSSv2

CVE-1999-1491

Published: 02/02/1996 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat linux 2.1

Exploits

source: wwwsecurityfocuscom/bid/354/info Abuse is a game that is included with RedHat Linux 21 in the games package The console version, abuseconsole, is suid-root and will load the program sndrv as root without checking for an absolute pathname This means that sndrv can be substituted in another directory by a regular user and used t ...