changepassword.cgi in ChangePassword 0.8, when installed setuid, allows local users to execute arbitrary code by modifying the PATH environment variable to point to a malicious make program.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Changepassword | Changepassword | 0.1 (including) | 0.1 (including) |
Changepassword | Changepassword | 0.2 (including) | 0.2 (including) |
Changepassword | Changepassword | 0.3 (including) | 0.3 (including) |
Changepassword | Changepassword | 0.4 (including) | 0.4 (including) |
Changepassword | Changepassword | 0.5 (including) | 0.5 (including) |
Changepassword | Changepassword | 0.6 (including) | 0.6 (including) |
Changepassword | Changepassword | 0.6.1 (including) | 0.6.1 (including) |
Changepassword | Changepassword | 0.7 (including) | 0.7 (including) |
Changepassword | Changepassword | 0.8 (including) | 0.8 (including) |