CVE Vulnerabilities

CVE-2001-0424

Published: Jul 02, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

Affected Software

NameVendorStart VersionEnd Version
BubblemonTimecop1.0 (including)1.0 (including)
BubblemonTimecop1.0pl1 (including)1.0pl1 (including)
BubblemonTimecop1.0pl2 (including)1.0pl2 (including)
BubblemonTimecop1.0pl3 (including)1.0pl3 (including)
BubblemonTimecop1.0pl4 (including)1.0pl4 (including)
BubblemonTimecop1.0pl6 (including)1.0pl6 (including)
BubblemonTimecop1.0pl7 (including)1.0pl7 (including)
BubblemonTimecop1.0pl8 (including)1.0pl8 (including)
BubblemonTimecop1.0pl9 (including)1.0pl9 (including)
BubblemonTimecop1.1 (including)1.1 (including)
BubblemonTimecop1.1test1 (including)1.1test1 (including)
BubblemonTimecop1.1test2 (including)1.1test2 (including)
BubblemonTimecop1.1test3 (including)1.1test3 (including)
BubblemonTimecop1.1test4 (including)1.1test4 (including)
BubblemonTimecop1.1test5 (including)1.1test5 (including)
BubblemonTimecop1.1test6 (including)1.1test6 (including)
BubblemonTimecop1.1test7 (including)1.1test7 (including)
BubblemonTimecop1.2 (including)1.2 (including)
BubblemonTimecop1.2test1 (including)1.2test1 (including)
BubblemonTimecop1.3 (including)1.3 (including)
BubblemonTimecop1.21 (including)1.21 (including)
BubblemonTimecop1.21test1 (including)1.21test1 (including)
BubblemonTimecop1.22 (including)1.22 (including)
BubblemonTimecop1.23 (including)1.23 (including)
BubblemonTimecop1.31 (including)1.31 (including)

References