Lucene search

K
cve[email protected]CVE-2001-0424
HistoryJul 02, 2001 - 4:00 a.m.

CVE-2001-0424

2001-07-0204:00:00
web.nvd.nist.gov
23
cve-2001-0424
bubblemon 1.31
privilege misuse
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.7%

BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

Affected configurations

NVD
Node
timecopbubblemonMatch1.0
OR
timecopbubblemonMatch1.0pl1
OR
timecopbubblemonMatch1.0pl2
OR
timecopbubblemonMatch1.0pl3
OR
timecopbubblemonMatch1.0pl4
OR
timecopbubblemonMatch1.0pl6
OR
timecopbubblemonMatch1.0pl7
OR
timecopbubblemonMatch1.0pl8
OR
timecopbubblemonMatch1.0pl9
OR
timecopbubblemonMatch1.1
OR
timecopbubblemonMatch1.1test1
OR
timecopbubblemonMatch1.1test2
OR
timecopbubblemonMatch1.1test3
OR
timecopbubblemonMatch1.1test4
OR
timecopbubblemonMatch1.1test5
OR
timecopbubblemonMatch1.1test6
OR
timecopbubblemonMatch1.1test7
OR
timecopbubblemonMatch1.2
OR
timecopbubblemonMatch1.2test1
OR
timecopbubblemonMatch1.3
OR
timecopbubblemonMatch1.21
OR
timecopbubblemonMatch1.21test1
OR
timecopbubblemonMatch1.22
OR
timecopbubblemonMatch1.23
OR
timecopbubblemonMatch1.31
Node
freebsdfreebsdMatch6.2stable

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.7%

Related for CVE-2001-0424