CVE Vulnerabilities

CVE-2001-1324

Published: Jun 26, 2001 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.

Affected Software

Name Vendor Start Version End Version
Idtools Paul_jarc 2001-05-31 (including) 2001-05-31 (including)
Idtools Paul_jarc 2001-06-08 (including) 2001-06-08 (including)

References