CVE-2004-0157

x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xonix:xonix:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:47

Type Values Removed Values Added
References () http://secunia.com/advisories/11382 - () http://secunia.com/advisories/11382 -
References () http://securitytracker.com/id?1009789 - () http://securitytracker.com/id?1009789 -
References () http://shellcode.org/Advisories/XONIX.txt - () http://shellcode.org/Advisories/XONIX.txt -
References () http://www.debian.org/security/2004/dsa-484 - Patch, Vendor Advisory () http://www.debian.org/security/2004/dsa-484 - Patch, Vendor Advisory
References () http://www.osvdb.org/5358 - () http://www.osvdb.org/5358 -
References () http://www.securityfocus.com/bid/10149 - () http://www.securityfocus.com/bid/10149 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/15873 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/15873 -

Information

Published : 2004-06-01 04:00

Updated : 2024-11-20 23:47


NVD link : CVE-2004-0157

Mitre link : CVE-2004-0157

CVE.ORG link : CVE-2004-0157


JSON object : View

Products Affected

xonix

  • xonix