CVE Vulnerabilities

CVE-2001-1374

Published: Jul 19, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.

Affected Software

NameVendorStart VersionEnd Version
ExpectDon_libes0 (including)0 (including)
ExpectDon_libes1 (including)1 (including)
ExpectDon_libes2 (including)2 (including)
ExpectDon_libes3 (including)3 (including)
ExpectDon_libes4 (including)4 (including)
ExpectDon_libes5.0 (including)5.0 (including)
ExpectDon_libes5.1 (including)5.1 (including)
ExpectDon_libes5.2 (including)5.2 (including)
ExpectDon_libes5.3 (including)5.3 (including)
ExpectDon_libes5.4 (including)5.4 (including)
ExpectDon_libes5.5 (including)5.5 (including)
ExpectDon_libes5.6 (including)5.6 (including)
ExpectDon_libes5.7 (including)5.7 (including)
ExpectDon_libes5.8 (including)5.8 (including)
ExpectDon_libes5.9 (including)5.9 (including)
ExpectDon_libes5.10 (including)5.10 (including)
ExpectDon_libes5.11 (including)5.11 (including)
ExpectDon_libes5.12 (including)5.12 (including)
ExpectDon_libes5.13 (including)5.13 (including)
ExpectDon_libes5.14 (including)5.14 (including)
ExpectDon_libes5.15 (including)5.15 (including)
ExpectDon_libes5.16 (including)5.16 (including)
ExpectDon_libes5.17 (including)5.17 (including)
ExpectDon_libes5.18 (including)5.18 (including)
ExpectDon_libes5.19 (including)5.19 (including)
ExpectDon_libes5.20 (including)5.20 (including)
ExpectDon_libes5.21 (including)5.21 (including)
ExpectDon_libes5.22 (including)5.22 (including)
ExpectDon_libes5.23 (including)5.23 (including)
ExpectDon_libes5.24 (including)5.24 (including)
ExpectDon_libes5.25 (including)5.25 (including)
ExpectDon_libes5.26 (including)5.26 (including)
ExpectDon_libes5.27 (including)5.27 (including)
ExpectDon_libes5.28 (including)5.28 (including)
ExpectDon_libes5.29 (including)5.29 (including)
ExpectDon_libes5.30 (including)5.30 (including)
ExpectDon_libes5.31 (including)5.31 (including)
LinuxConectiva6.0 (including)6.0 (including)
LinuxConectiva7.0 (including)7.0 (including)
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*

References