CVE Vulnerabilities

CVE-2000-0118

Published: Jun 09, 1999 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.

Affected Software

Name Vendor Start Version End Version
Linux Redhat 2.0 (including) 2.0 (including)
Linux Redhat 2.1 (including) 2.1 (including)
Linux Redhat 3.0.3 (including) 3.0.3 (including)
Linux Redhat 4.0 (including) 4.0 (including)
Linux Redhat 4.1 (including) 4.1 (including)
Linux Redhat 4.2 (including) 4.2 (including)
Linux Redhat 5.0 (including) 5.0 (including)
Linux Redhat 5.1 (including) 5.1 (including)
Linux Redhat 5.2 (including) 5.2 (including)
Linux Redhat 6.0 (including) 6.0 (including)
Linux Redhat 6.1 (including) 6.1 (including)
Solaris Sun * *
Solaris Sun 1.1.3-u1 (including) 1.1.3-u1 (including)
Solaris Sun 1.1.4 (including) 1.1.4 (including)
Solaris Sun 2.4 (including) 2.4 (including)
Sunos Sun - (including) - (including)
Sunos Sun 4.1.3 (including) 4.1.3 (including)
Sunos Sun 4.1.4 (including) 4.1.4 (including)
Sunos Sun 5.0 (including) 5.0 (including)
Sunos Sun 5.1 (including) 5.1 (including)
Sunos Sun 5.2 (including) 5.2 (including)
Sunos Sun 5.3 (including) 5.3 (including)
Sunos Sun 5.4 (including) 5.4 (including)
Sunos Sun 5.5 (including) 5.5 (including)

References