Vulnerability Name: | CVE-2000-0186 (CCN-4048) | ||||||||
Assigned: | 2000-02-28 | ||||||||
Published: | 2000-02-28 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Caldera International, Inc. Security Advisory CSSA-2000-004.0 Security problem (setuid) with dump Source: CCN Type: BugTraq Mailing List, Mon Feb 28 2000 - 00:17:33 CST [ Hackerslab bug_paper ] Linux dump buffer overflow Source: CCN Type: Conectiva Linux Announcement CLSA-2000:237 dump Source: CCN Type: BugTraq Mailing List, Tue Jul 11 2000 - 17:25:02 CDT MDKSA-2000:018 dump update Source: MITRE Type: CNA CVE-2000-0186 Source: CCN Type: TurboLinux Security Announcement TLSA2000007-1 dump-0.4b11-1 and earlier Source: CCN Type: RHSA-2000-100 Setuid bits are removed on dump to prevent exploit Source: CCN Type: OSVDB ID: 1239 Linux ext2fs Backup Package dump Command Line Argument Overflow Source: REDHAT Type: UNKNOWN RHSA-2000:100 Source: BID Type: UNKNOWN 1020 Source: CCN Type: BID-1020 Multiple Vendor "dump" Buffer Overflow Vulnerability Source: XF Type: UNKNOWN linux-dump-bo(4048) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |