PT-2001-2234 · Netbsd · Netbsd

Publicado

2001-08-23

·

Atualizado

2017-12-19

·

CVE-2001-1091

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NetBSD versions 1.4.x through 1.5.1
Description The issue concerns the dump and dump lfs commands, which do not properly drop privileges. This could allow local users to gain privileges via the RCMD CMD environment variable.
Recommendations For NetBSD versions 1.4.x through 1.5.1, consider restricting access to the dump and dump lfs commands until a proper fix is applied to ensure these commands drop privileges correctly. As a temporary workaround, avoid using the RCMD CMD environment variable with these commands to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1091

Produtos afetados

Netbsd