PT-2001-2176 · Freebsd+1 · Libutil+2

CVE-2001-1029

·

Publicado

2001-09-20

·

Atualizado

2024-07-08

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSH on FreeBSD versions 4.4 and earlier
Description The issue allows local users to bypass capabilities checks and read arbitrary files by specifying alternate copyright or welcome files, due to libutil in OpenSSH not dropping privileges before verifying the capabilities for reading these files.
Recommendations For OpenSSH on FreeBSD versions 4.4 and earlier, consider updating to a version where this issue is resolved, or as a temporary workaround, restrict access to the copyright and welcome files to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
CVE-2001-1029

Produtos afetados

Alt Linux
Openssh
Libutil