Description
dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.
Affected products
- RedHat / linux6.2 – 6.2
- trustix / secure_linux1.1 – 1.1
Exploits & proofs of concept
- exploit-dbdump 0.4b15 (RedHat 6.2) - Local Privilege Escalationby mat
- exploit-dbdump 0.4b15 - Local Privilege Escalationby mat
Updated 16m ago · 8 sources