LWN.net Logo

slim: arbitrary code execution

Package(s):slim CVE #(s):CVE-2010-2945
Created:September 9, 2010 Updated:September 15, 2010
Description:

From the Red Hat bugzilla entry:

It was reported that SLiM versions prior to 1.3.1 assigned logged-in users a predefined PATH which included './', which could allow for unintentional code execution.

Alerts:
Fedora FEDORA-2010-13890 2010-09-01
Fedora FEDORA-2010-13897 2010-09-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds