CVE Vulnerabilities

CVE-2000-0393

Published: May 16, 2000 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The KDE kscd program does not drop privileges when executing a program specified in a users SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.

Affected Software

NameVendorStart VersionEnd Version
KdeKde1.1 (including)1.1 (including)
KdeKde1.1.1 (including)1.1.1 (including)
KdeKde1.2 (including)1.2 (including)
KdeKde2.0_beta (including)2.0_beta (including)

References