Vulnerability Name: | CVE-2001-1145 (CCN-8715) | ||||||||
Assigned: | 2001-05-30 | ||||||||
Published: | 2001-05-30 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories. | ||||||||
CVSS v3 Severity: | 8.1 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.2 Medium (CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: FreeBSD Security Advisory FreeBSD-SA-01:40 fts(3) routines contain race condition [REVISED] Source: FREEBSD Type: UNKNOWN FreeBSD-SA-01:40 Source: CCN Type: NetBSD Security Advisory NetBSD-SA2001-016 unsafe chdir usage in fts(3) Source: NETBSD Type: Patch, Vendor Advisory NetBSD-SA2001-016 Source: MITRE Type: CNA CVE-2001-1145 Source: XF Type: UNKNOWN bsd-fts-race-condition(8715) Source: CCN Type: OpenBSD Security Advisory 029: SECURITY FIX: May 30, 2001 Source: OPENBSD Type: Patch 20010530 029: SECURITY FIX: May 30, 2001 Source: OSVDB Type: UNKNOWN 5466 Source: CCN Type: OSVDB ID: 5466 Multiple BSD fts Routines chdir Arbitrary Directory Access Source: BID Type: UNKNOWN 3205 Source: CCN Type: BID-3205 Multiple BSD FTS Directory Traversal Race Condition Vulnerability Source: XF Type: UNKNOWN bsd-fts-race-condition(8715) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |