Vulnerability Name:

CVE-2001-0823 (CCN-6724)

Assigned:2001-06-18
Published:2001-06-18
Updated:2017-10-10
Summary:The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR).
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
2.6 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:File Manipulation
References:Source: CCN
Type: SGI Security Advisory 20010601-01-A
PCP pmpost vulnerability

Source: SGI
Type: Patch
20010601-01-A

Source: CCN
Type: SGI Security Advisory 20010601-01-I
pmpost vulnerability

Source: CCN
Type: BugTraq Mailing List, Mon Jun 18 2001 - 12:11:20 CDT
pmpost - another nice symlink follower

Source: BUGTRAQ
Type: Patch, Vendor Advisory
20010619 Re: pmpost - another nice symlink follower

Source: CCN
Type: BugTraq Mailing List, Thu Jun 21 2001 - 00:21:16 CDT
[ANNOUNCE] SGI Performance Co-Pilot 2.2.1-3 now available

Source: MITRE
Type: CNA
CVE-2001-0823

Source: BUGTRAQ
Type: UNKNOWN
20010618 pmpost - another nice symlink follower

Source: CCN
Type: OSS SGI Download Page
Index of /projects/pcp/download

Source: CCN
Type: CIAC Information Bulletin L-099
SGI PCP Pmpost Symlink Vulnerability

Source: CCN
Type: OSVDB ID: 1870
Performance Co-Pilot pmpost Symlink Privilege Escalation

Source: BID
Type: Exploit, Patch, Vendor Advisory
2887

Source: CCN
Type: BID-2887
SGI Performance Co-Pilot pmpost Symbolic Link Vulnerability

Source: XF
Type: UNKNOWN
irix-pcp-pmpost-symlink(6724)

Source: XF
Type: UNKNOWN
irix-pcp-pmpost-symlink(6724)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sgi:performance_co-pilot:2.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.8:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.9:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.10:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.11:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:sgi:irix:6.5:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.2:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.3:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.4:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.7:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.5:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.6:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.8:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.9:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.10:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.11:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.12:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.13:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.14:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.15:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.16:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.19:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.20:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.21:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.24:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.22:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.23:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.25:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.22m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.21m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.21f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.26:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.27:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.10f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.10m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.11f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.11m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.12f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.12m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.13f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.13m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.14f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.14m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.15f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.15m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.16f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.16m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.17:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.17f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.17m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.18:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.18f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.18m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.19f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.19m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.20f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.20m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.2f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.2m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.3f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.3m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.4f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.4m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.5f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.5m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.6f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.6m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.7f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.7m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.8f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.8m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.9f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.9m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5_20:*:*:*:*:*:*:*
  • AND
  • cpe:/a:sgi:performance_co-pilot:2.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.10:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.8:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.1.9:*:*:*:*:*:*:*
  • OR cpe:/a:sgi:performance_co-pilot:2.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sgi performance co-pilot 2.1.1
    sgi performance co-pilot 2.1.2
    sgi performance co-pilot 2.1.3
    sgi performance co-pilot 2.1.4
    sgi performance co-pilot 2.1.5
    sgi performance co-pilot 2.1.6
    sgi performance co-pilot 2.1.7
    sgi performance co-pilot 2.1.8
    sgi performance co-pilot 2.1.9
    sgi performance co-pilot 2.1.10
    sgi performance co-pilot 2.1.11
    sgi performance co-pilot 2.2
    sgi irix 6.5
    sgi irix 6.5.1
    sgi irix 6.5.2
    sgi irix 6.5.3
    sgi irix 6.5.4
    sgi irix 6.5.7
    sgi irix 6.5.5
    sgi irix 6.5.6
    sgi irix 6.5.8
    sgi irix 6.5.9
    sgi irix 6.5.10
    sgi irix 6.5.11
    sgi irix 6.5.12
    sgi irix 6.5.13
    sgi irix 6.5.14
    sgi irix 6.5.15
    sgi irix 6.5.16
    sgi irix 6.5.19
    sgi irix 6.5.20
    sgi irix 6.5.21
    sgi irix 6.5.24
    sgi irix 6.5.22
    sgi irix 6.5.23
    sgi irix 6.5.25
    sgi irix 6.5.22m
    sgi irix 6.5.21m
    sgi irix 6.5.21f
    sgi irix 6.5.26
    sgi irix 6.5.27
    sgi irix 6.5.10f
    sgi irix 6.5.10m
    sgi irix 6.5.11f
    sgi irix 6.5.11m
    sgi irix 6.5.12f
    sgi irix 6.5.12m
    sgi irix 6.5.13f
    sgi irix 6.5.13m
    sgi irix 6.5.14f
    sgi irix 6.5.14m
    sgi irix 6.5.15f
    sgi irix 6.5.15m
    sgi irix 6.5.16f
    sgi irix 6.5.16m
    sgi irix 6.5.17
    sgi irix 6.5.17f
    sgi irix 6.5.17m
    sgi irix 6.5.18
    sgi irix 6.5.18f
    sgi irix 6.5.18m
    sgi irix 6.5.19f
    sgi irix 6.5.19m
    sgi irix 6.5.20f
    sgi irix 6.5.20m
    sgi irix 6.5.2f
    sgi irix 6.5.2m
    sgi irix 6.5.3f
    sgi irix 6.5.3m
    sgi irix 6.5.4f
    sgi irix 6.5.4m
    sgi irix 6.5.5f
    sgi irix 6.5.5m
    sgi irix 6.5.6f
    sgi irix 6.5.6m
    sgi irix 6.5.7f
    sgi irix 6.5.7m
    sgi irix 6.5.8f
    sgi irix 6.5.8m
    sgi irix 6.5.9f
    sgi irix 6.5.9m
    sgi irix 6.5_20
    sgi performance co-pilot 2.1.1
    sgi performance co-pilot 2.1.10
    sgi performance co-pilot 2.1.2
    sgi performance co-pilot 2.1.3
    sgi performance co-pilot 2.1.4
    sgi performance co-pilot 2.1.5
    sgi performance co-pilot 2.1.6
    sgi performance co-pilot 2.1.7
    sgi performance co-pilot 2.1.8
    sgi performance co-pilot 2.1.9
    sgi performance co-pilot 2.2