PT-2001-2234 · Netbsd · Netbsd
Publicado
2001-08-23
·
Atualizado
2017-12-19
·
CVE-2001-1091
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NetBSD versions 1.4.x through 1.5.1
Description
The issue concerns the dump and dump lfs commands, which do not properly drop privileges. This could allow local users to gain privileges via the RCMD CMD environment variable.
Recommendations
For NetBSD versions 1.4.x through 1.5.1, consider restricting access to the dump and dump lfs commands until a proper fix is applied to ensure these commands drop privileges correctly. As a temporary workaround, avoid using the RCMD CMD environment variable with these commands to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Netbsd