7.2
CVSSv2

CVE-2006-7191

Published: 03/04/2007 Updated: 05/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in lamdaemon.pl in LDAP Account Manager (LAM) prior to 1.0.0 allows local users to gain privileges via a modified PATH that points to a malicious rm program.

Vulnerable Product Search on Vulmon Subscribe to Product

ldap account manager ldap account manager

Vendor Advisories

Two vulnerabilities have been identified in the version of ldap-account-manager shipped with Debian 31 (sarge) CVE-2006-7191 An untrusted PATH vulnerability could allow a local attacker to execute arbitrary code with elevated privileges by providing a malicious rm executable and specifying a PATH environment variable referencing this ...