PT-2000-1718 · Gnu · Gnuserv

Published

2000-10-20

·

Updated

2016-10-18

·

CVE-2000-0786

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNU userv versions 1.0.0 and earlier
Description The issue is related to improper file descriptor swapping, which can corrupt the USERV GROUPS and USERV GIDS environmental variables. This corruption allows local users to bypass some access restrictions.
Recommendations For GNU userv versions 1.0.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0786

Affected Products

Gnuserv