Untrusted search path vulnerability in a certain Red Hat build script for Standards Based Linux Instrumentation for Manageability (sblim) libraries before 1-13a.el4_6.1 in Red Hat Enterprise Linux (RHEL) 4 and before 1-31.el5_2.1 in RHEL 5 allows local users to gain privileges via a malicious library in a certain subdirectory of /var/tmp related to an incorrect RPATH setting as demonstrated by a malicious library for tog-pegasus.