PT-2001-1038 · Red Hat+1 · Red Hat+5

Published

2001-07-19

·

Updated

2017-10-10

·

CVE-2001-1374

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions expect versions prior to 5.32 tclx-8.3 tcltk-8.3.3 tcllib-1.0 tcl-8.3.3
Description The issue allows local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd. Multiple vulnerabilities in the tclx, tcltk, tcllib, and tcl packages of the Red Hat Linux operating system can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally.
Recommendations For expect versions prior to 5.32, update to version 5.32 or later to resolve the issue. For tclx-8.3, tcltk-8.3.3, tcllib-1.0, and tcl-8.3.3, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07966
BDU:2015-07967
BDU:2015-07968
BDU:2015-07969
CVE-2001-1374

Affected Products

Red Hat
Expect
Tcl
Tcllib
Tcltk
Tclx