automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environment variable values instead of the values for the user used to run the mapped program, which allows local users to gain privileges via a Trojan horse program in the user home directory.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2015-03-18T16:00:00

Updated: 2024-08-06T13:10:51.178Z

Reserved: 2014-10-10T00:00:00

Link: CVE-2014-8169

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2015-03-18T16:59:00.063

Modified: 2024-11-21T02:18:42.137

Link: CVE-2014-8169

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-03-02T00:00:00Z

Links: CVE-2014-8169 - Bugzilla