PT-2001-1004 · Red Hat+1 · Red Hat+1

Publicado

2001-04-17

·

Atualizado

2017-10-10

·

CVE-2001-0873

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions uucp versions 1.06.1 and earlier Taylor UUCP package (affected versions not specified)
Description The issue affects the uucp package in Debian GNU/Linux and Red Hat Linux operating systems, potentially leading to breaches of confidentiality, integrity, and availability of protected information. A local attacker can exploit this issue. Technical details include the uuxqt component of the Taylor UUCP package, which fails to properly remove dangerous long options. This allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option, using variables like --config to manipulate the system.
Recommendations For uucp version 1.06.1, consider restricting access to the uuxqt component until a patch is available. For Taylor UUCP package, as a temporary workaround, consider disabling the uux function with the --config option to prevent privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-02543
BDU:2015-07837
CVE-2001-0873

Produtos afetados

Debian
Red Hat