bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bestcrypt | Jetico | * | 0.7 (including) |