Arbitrary Code Execution via Path Manipulation in xonix 1.4 and Earlier

Arbitrary Code Execution via Path Manipulation in xonix 1.4 and Earlier

CVE-2004-0157 · MEDIUM Severity

AV:L/AC:L/AU:N/C:P/I:P/A:P

x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.

Learn more about our User Device Pen Test.