PT-2001-2234 · Netbsd · Netbsd
Published
2001-08-23
·
Updated
2017-12-19
·
CVE-2001-1091
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NetBSD versions 1.4.x through 1.5.1
Description
The issue concerns the dump and dump lfs commands, which do not properly drop privileges. This could allow local users to gain privileges via the RCMD CMD environment variable.
Recommendations
For NetBSD versions 1.4.x through 1.5.1, consider restricting access to the dump and dump lfs commands until a proper fix is applied to ensure these commands drop privileges correctly. As a temporary workaround, avoid using the RCMD CMD environment variable with these commands to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netbsd