Lucene search

K
cve[email protected]CVE-2000-0118
HistoryFeb 08, 2000 - 5:00 a.m.

CVE-2000-0118

2000-02-0805:00:00
web.nvd.nist.gov
24
red hat
linux su
cve-2000-0118
password guessing
brute force
security vulnerability

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

0.4%

The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.

Affected configurations

NVD
Node
redhatlinuxMatch2.0
OR
redhatlinuxMatch2.1
OR
redhatlinuxMatch3.0.3
OR
redhatlinuxMatch4.0
OR
redhatlinuxMatch4.1
OR
redhatlinuxMatch4.2
OR
redhatlinuxMatch5.0
OR
redhatlinuxMatch5.1
OR
redhatlinuxMatch5.2alpha
OR
redhatlinuxMatch5.2i386
OR
redhatlinuxMatch5.2sparc
OR
redhatlinuxMatch6.0alpha
OR
redhatlinuxMatch6.0i386
OR
redhatlinuxMatch6.0sparc
OR
redhatlinuxMatch6.1alpha
OR
redhatlinuxMatch6.1i386
OR
redhatlinuxMatch6.1sparc
OR
sunsolarisx86
OR
sunsolarisMatch1.1.3u1
OR
sunsolarisMatch1.1.4jl
OR
sunsolarisMatch2.4x86
OR
sunsunosMatch-
OR
sunsunosMatch4.1.3
OR
sunsunosMatch4.1.4
OR
sunsunosMatch5.0
OR
sunsunosMatch5.1
OR
sunsunosMatch5.2
OR
sunsunosMatch5.3
OR
sunsunosMatch5.4
OR
sunsunosMatch5.5

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

0.4%

Related for CVE-2000-0118