PT-2001-1213 · Bb · Big Brother
Published
2001-01-09
·
Updated
2008-09-05
·
CVE-2000-1177
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Big Brother (BB) versions prior to 1.5d3
Description:
The issue allows remote attackers to determine the existence of files and user IDs by specifying the target file in the
HISTFILE parameter. This is related to the scripts bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh.Recommendations:
For versions prior to 1.5d3, update to version 1.5d3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
HISTFILE parameter in the affected scripts to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Big Brother