CVE Vulnerabilities

CVE-2001-0424

Published: Jul 02, 2001 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

Affected Software

Name Vendor Start Version End Version
Bubblemon Timecop 1.0 (including) 1.0 (including)
Bubblemon Timecop 1.0pl1 (including) 1.0pl1 (including)
Bubblemon Timecop 1.0pl2 (including) 1.0pl2 (including)
Bubblemon Timecop 1.0pl3 (including) 1.0pl3 (including)
Bubblemon Timecop 1.0pl4 (including) 1.0pl4 (including)
Bubblemon Timecop 1.0pl6 (including) 1.0pl6 (including)
Bubblemon Timecop 1.0pl7 (including) 1.0pl7 (including)
Bubblemon Timecop 1.0pl8 (including) 1.0pl8 (including)
Bubblemon Timecop 1.0pl9 (including) 1.0pl9 (including)
Bubblemon Timecop 1.1 (including) 1.1 (including)
Bubblemon Timecop 1.1test1 (including) 1.1test1 (including)
Bubblemon Timecop 1.1test2 (including) 1.1test2 (including)
Bubblemon Timecop 1.1test3 (including) 1.1test3 (including)
Bubblemon Timecop 1.1test4 (including) 1.1test4 (including)
Bubblemon Timecop 1.1test5 (including) 1.1test5 (including)
Bubblemon Timecop 1.1test6 (including) 1.1test6 (including)
Bubblemon Timecop 1.1test7 (including) 1.1test7 (including)
Bubblemon Timecop 1.2 (including) 1.2 (including)
Bubblemon Timecop 1.2test1 (including) 1.2test1 (including)
Bubblemon Timecop 1.3 (including) 1.3 (including)
Bubblemon Timecop 1.21 (including) 1.21 (including)
Bubblemon Timecop 1.21test1 (including) 1.21test1 (including)
Bubblemon Timecop 1.22 (including) 1.22 (including)
Bubblemon Timecop 1.23 (including) 1.23 (including)
Bubblemon Timecop 1.31 (including) 1.31 (including)

References