stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2004-10-26T04:00:00
Updated: 2017-10-10T00:57:01
Reserved: 2004-10-19T00:00:00
Link: CVE-2004-0965
JSON object: View
NVD Information
Status : Modified
Published: 2005-02-09T05:00:00.000
Modified: 2017-10-11T01:29:38.873
Link: CVE-2004-0965
JSON object: View
Redhat Information
No data.
CWE