CVE Vulnerabilities

CVE-2000-0118

Published: Jun 09, 1999 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.

Affected Software

NameVendorStart VersionEnd Version
LinuxRedhat2.0 (including)2.0 (including)
LinuxRedhat2.1 (including)2.1 (including)
LinuxRedhat3.0.3 (including)3.0.3 (including)
LinuxRedhat4.0 (including)4.0 (including)
LinuxRedhat4.1 (including)4.1 (including)
LinuxRedhat4.2 (including)4.2 (including)
LinuxRedhat5.0 (including)5.0 (including)
LinuxRedhat5.1 (including)5.1 (including)
LinuxRedhat5.2 (including)5.2 (including)
LinuxRedhat6.0 (including)6.0 (including)
LinuxRedhat6.1 (including)6.1 (including)
SolarisSun**
SolarisSun1.1.3-u1 (including)1.1.3-u1 (including)
SolarisSun1.1.4 (including)1.1.4 (including)
SolarisSun2.4 (including)2.4 (including)
SunosSun- (including)- (including)
SunosSun4.1.3 (including)4.1.3 (including)
SunosSun4.1.4 (including)4.1.4 (including)
SunosSun5.0 (including)5.0 (including)
SunosSun5.1 (including)5.1 (including)
SunosSun5.2 (including)5.2 (including)
SunosSun5.3 (including)5.3 (including)
SunosSun5.4 (including)5.4 (including)
SunosSun5.5 (including)5.5 (including)

References