7.2
CVSSv2

CVE-2004-0850

Published: 23/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Star prior to 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.

Vulnerable Product Search on Vulmon Subscribe to Product

joerg schilling star tape archiver 1.5_a45