Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.sh, which allows local users to gain privileges by replacing this files content with arbitrary shell commands.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Filr | Novell | * | 1.2 (including) |
Filr | Novell | * | 2.0 (including) |