CVE-2001-1029
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/09/2001
Last modified:
20/11/2024
Description
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.
Impact
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:openbsd:openssh:4.5:*:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* | 4.4 (including) |
To consult the complete list of CPE names with products and versions, see this page