PT-2001-1213 · Bb · Big Brother

Published

2001-01-09

·

Updated

2008-09-05

·

CVE-2000-1177

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Big Brother (BB) versions prior to 1.5d3
Description: The issue allows remote attackers to determine the existence of files and user IDs by specifying the target file in the HISTFILE parameter. This is related to the scripts bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh.
Recommendations: For versions prior to 1.5d3, update to version 1.5d3 or later to resolve the issue. As a temporary workaround, consider restricting access to the HISTFILE parameter in the affected scripts to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-1177

Affected Products

Big Brother