PT-2001-2234 · Netbsd · Netbsd

Published

2001-08-23

·

Updated

2017-12-19

·

CVE-2001-1091

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NetBSD versions 1.4.x through 1.5.1
Description The issue concerns the dump and dump lfs commands, which do not properly drop privileges. This could allow local users to gain privileges via the RCMD CMD environment variable.
Recommendations For NetBSD versions 1.4.x through 1.5.1, consider restricting access to the dump and dump lfs commands until a proper fix is applied to ensure these commands drop privileges correctly. As a temporary workaround, avoid using the RCMD CMD environment variable with these commands to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1091

Affected Products

Netbsd