Lucene search

K
cve[email protected]CVE-2001-1375
HistoryApr 02, 2003 - 5:00 a.m.

CVE-2001-1375

2003-04-0205:00:00
web.nvd.nist.gov
23
cve-2001-1375
tcl/tk package
trojan horse
code execution
nvd.

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory.

Affected configurations

NVD
Node
conectivalinuxMatch6.0
OR
conectivalinuxMatch7.0
Node
redhatlinuxMatch7.0

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2001-1375