Untrusted search path vulnerability in lamdaemon.pl in LDAP Account Manager (LAM) before 1.0.0 allows local users to gain privileges via a modified PATH that points to a malicious rm program.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ldap_account_manager | Ldap_account_manager | * | 1.0_rc2 (including) |
Ldap-account-manager | Ubuntu | dapper | * |
Ldap-account-manager | Ubuntu | upstream | * |