automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environment variable values instead of the values for the user used to run the mapped program, which allows local users to gain privileges via a Trojan horse program in the user home directory.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2015-03-18T16:00:00

Updated: 2016-12-30T16:57:01

Reserved: 2014-10-10T00:00:00


Link: CVE-2014-8169

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2015-03-18T16:59:00.063

Modified: 2023-02-13T00:44:12.453


Link: CVE-2014-8169

JSON object: View

cve-icon Redhat Information

No data.

CWE