Security Advisory
CVE-2000-1072
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.