CVE Vulnerabilities

CVE-2003-1167

Published: Dec 31, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.

Affected Software

NameVendorStart VersionEnd Version
KpopupGernot_stocker0.9.1 (including)0.9.1 (including)
KpopupGernot_stocker0.9.5_pre2 (including)0.9.5_pre2 (including)

References