Security Advisory

CVE-2004-0965

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2004-10-26 04:00:00
Last updated 2024-08-08 00:38:59
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.