tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory.
| Software | From | Fixed in |
|---|---|---|
| conectiva / linux | 6.0 | 6.0.x |
| conectiva / linux | 7.0 | 7.0.x |
| redhat / linux | 7.0 | 7.0.x |