OSVDB ID: 9778

Title: Star RSH Environment Variable Privilege Escalation

Info

Disclosure

Sep 08, 2004

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Star contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the applications is configured to use SSH for remote tape access. This flaw may lead to a loss of integrity. No further details have been provided.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 1.5_alpha46 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Jörg Schilling

Star

1.5_alpha45

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/9778