CVE-2003-1167

Publication date

2005-05-10 04:00:00

Family

mitre

State

PUBLISHED

Description

misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.