Description
startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of other users running startkde via Trojan horse libraries.
Affected products
- caldera / openlinux_server3.1.1 – 3.1.1
- caldera / openlinux_workstation3.1.1 – 3.1.1