Privilege Escalation Vulnerability in Star before 1.5_alpha46

Privilege Escalation Vulnerability in Star before 1.5_alpha46

CVE-2004-0850 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.

Learn more about our External Network Penetration Testing.