CVE Vulnerabilities

CVE-2000-0393

Published: May 16, 2000 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The KDE kscd program does not drop privileges when executing a program specified in a users SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.

Affected Software

Name Vendor Start Version End Version
Kde Kde 1.1 (including) 1.1 (including)
Kde Kde 1.1.1 (including) 1.1.1 (including)
Kde Kde 1.2 (including) 1.2 (including)
Kde Kde 2.0_beta (including) 2.0_beta (including)

References