CVE Vulnerabilities

CVE-2001-0424

Published: Jul 02, 2001 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

Affected Software

Name Vendor Start Version End Version
Bubblemon Timecop 1.0 (including) 1.0 (including)
Bubblemon Timecop 1.0pl1 (including) 1.0pl1 (including)
Bubblemon Timecop 1.0pl2 (including) 1.0pl2 (including)
Bubblemon Timecop 1.0pl3 (including) 1.0pl3 (including)
Bubblemon Timecop 1.0pl4 (including) 1.0pl4 (including)
Bubblemon Timecop 1.0pl6 (including) 1.0pl6 (including)
Bubblemon Timecop 1.0pl7 (including) 1.0pl7 (including)
Bubblemon Timecop 1.0pl8 (including) 1.0pl8 (including)
Bubblemon Timecop 1.0pl9 (including) 1.0pl9 (including)
Bubblemon Timecop 1.1 (including) 1.1 (including)
Bubblemon Timecop 1.1test1 (including) 1.1test1 (including)
Bubblemon Timecop 1.1test2 (including) 1.1test2 (including)
Bubblemon Timecop 1.1test3 (including) 1.1test3 (including)
Bubblemon Timecop 1.1test4 (including) 1.1test4 (including)
Bubblemon Timecop 1.1test5 (including) 1.1test5 (including)
Bubblemon Timecop 1.1test6 (including) 1.1test6 (including)
Bubblemon Timecop 1.1test7 (including) 1.1test7 (including)
Bubblemon Timecop 1.2 (including) 1.2 (including)
Bubblemon Timecop 1.2test1 (including) 1.2test1 (including)
Bubblemon Timecop 1.3 (including) 1.3 (including)
Bubblemon Timecop 1.21 (including) 1.21 (including)
Bubblemon Timecop 1.21test1 (including) 1.21test1 (including)
Bubblemon Timecop 1.22 (including) 1.22 (including)
Bubblemon Timecop 1.23 (including) 1.23 (including)
Bubblemon Timecop 1.31 (including) 1.31 (including)

References