PT-2001-2176 · Freebsd+1 · Libutil+2

Published

2001-09-20

·

Updated

2024-07-08

·

CVE-2001-1029

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSH on FreeBSD versions 4.4 and earlier
Description The issue allows local users to bypass capabilities checks and read arbitrary files by specifying alternate copyright or welcome files, due to libutil in OpenSSH not dropping privileges before verifying the capabilities for reading these files.
Recommendations For OpenSSH on FreeBSD versions 4.4 and earlier, consider updating to a version where this issue is resolved, or as a temporary workaround, restrict access to the copyright and welcome files to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
CVE-2001-1029

Affected Products

Alt Linux
Openssh
Libutil