CVE-2001-1091

The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:netbsd:netbsd:1.4:*:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.4.1:*:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.4.2:*:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.4.3:*:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.5:*:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.5.1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:36

Type Values Removed Values Added
References () ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-014.txt.asc - () ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-014.txt.asc -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/7037 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/7037 -

Information

Published : 2001-08-23 04:00

Updated : 2024-11-20 23:36


NVD link : CVE-2001-1091

Mitre link : CVE-2001-1091

CVE.ORG link : CVE-2001-1091


JSON object : View

Products Affected

netbsd

  • netbsd