Lucene search

K
cve[email protected]CVE-2001-1029
HistorySep 01, 2004 - 4:00 a.m.

CVE-2001-1029

2004-09-0104:00:00
web.nvd.nist.gov
33
openssh
freebsd 4.4
privilege escalation
file access
cve-2001-1029

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

0.4%

libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.

Affected configurations

NVD
Node
openbsdopensshMatch4.5
Node
freebsdfreebsdRange4.4
CPENameOperatorVersion
openbsd:opensshopenbsd openssheq4.5

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

0.4%

Related for CVE-2001-1029