CVE-2008-2378

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
26/11/2008
Last modified:
09/04/2025

Description

Untrusted search path vulnerability in hfkernel in hf 0.7.3 and 0.8 allows local users to gain privileges via a Trojan horse killall program in a directory in the PATH, related to improper handling of the -k option.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hf:hf:0.7.3:*:*:*:*:*:*:*
cpe:2.3:a:hf:hf:0.8:*:*:*:*:*:*:*