CVE-2001-1374

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2001
Last modified:
10/10/2017

Description

expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:don_libes:expect:0:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:1:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:2:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:3:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:4:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:5.0:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:5.1:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:5.2:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:5.3:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:5.4:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:5.5:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:5.6:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:5.7:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:5.8:*:*:*:*:*:*:*
cpe:2.3:a:don_libes:expect:5.9:*:*:*:*:*:*:*