7.2
CVSSv2

CVE-2000-0393

Published: 16/05/2000 Updated: 10/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde 1.1

kde kde 1.1.1

kde kde 1.2

kde kde 2.0_beta

Exploits

source: wwwsecurityfocuscom/bid/1206/info Some linux distributions (SuSE 64 reported) ship with kscd (a CD player for the KDE Desktop) sgid disk kscd uses the contents of the 'SHELL' environment variable to execute a browser This makes it possible to obtain a sgid 'disk' shell Using these privileges along with code provided in the ...