CVE Vulnerabilities

CVE-2000-0118

Published: Jun 09, 1999 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.

Affected Software

Name Vendor Start Version End Version
Linux Redhat 2.0 (including) 2.0 (including)
Linux Redhat 2.1 (including) 2.1 (including)
Linux Redhat 3.0.3 (including) 3.0.3 (including)
Linux Redhat 4.0 (including) 4.0 (including)
Linux Redhat 4.1 (including) 4.1 (including)
Linux Redhat 4.2 (including) 4.2 (including)
Linux Redhat 5.0 (including) 5.0 (including)
Linux Redhat 5.1 (including) 5.1 (including)
Linux Redhat 5.2 (including) 5.2 (including)
Linux Redhat 6.0 (including) 6.0 (including)
Linux Redhat 6.1 (including) 6.1 (including)
Solaris Sun * *
Solaris Sun 1.1.3-u1 (including) 1.1.3-u1 (including)
Solaris Sun 1.1.4 (including) 1.1.4 (including)
Solaris Sun 2.4 (including) 2.4 (including)
Sunos Sun - (including) - (including)
Sunos Sun 4.1.3 (including) 4.1.3 (including)
Sunos Sun 4.1.4 (including) 4.1.4 (including)
Sunos Sun 5.0 (including) 5.0 (including)
Sunos Sun 5.1 (including) 5.1 (including)
Sunos Sun 5.2 (including) 5.2 (including)
Sunos Sun 5.3 (including) 5.3 (including)
Sunos Sun 5.4 (including) 5.4 (including)
Sunos Sun 5.5 (including) 5.5 (including)

References