Privilege Escalation via Manipulated PATH Environment Variable in Maped in LuxMan 0.41

Privilege Escalation via Manipulated PATH Environment Variable in Maped in LuxMan 0.41

CVE-2002-1245 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

Maped in LuxMan 0.41 uses the user-provided search path to find and execute the gzip program, which allows local users to modify /dev/mem and gain privileges via a modified PATH environment variable that points to a Trojan horse gzip program.

Learn more about our User Device Pen Test.