Security Advisory
CVE-2001-1374
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.