lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.Referenceshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A430http://www.redhat.com/support/errata/RHSA-2003-169.htmlhttp://www.debian.org/security/2003/dsa-304http://www.redhat.com/support/errata/RHSA-2003-167.htmlhttp://www.turbolinux.com/security/TLSA-2003-35.txt