Vulnerability Name: | CVE-2001-1345 (CCN-6648) | ||||||||
Assigned: | 2001-06-05 | ||||||||
Published: | 2001-06-05 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20010604 Fatal flaw in BestCrypt <= v0.7 (Linux) Source: CCN Type: BugTraq Mailing List, Mon Jun 04 2001 - 19:23:54 CDT Fatal flaw in BestCrypt <= v0.7 (Linux) Source: MITRE Type: CNA CVE-2001-1345 Source: CONFIRM Type: UNKNOWN http://www.jetico.com/index.htm#/linux.htm Source: CCN Type: Jetico, Inc. Web site BestCrypt and BCWipe software for Linux Source: CCN Type: OSVDB ID: 1851 BestCrypt Arbitrary Privileged Program Execution Source: BID Type: Exploit, Patch, Vendor Advisory 2820 Source: CCN Type: BID-2820 BestCrypt Arbitrary Privileged Program Execution Vulnerability Source: XF Type: UNKNOWN bestcrypt-bctool-gain-privileges(6648) Source: XF Type: UNKNOWN bestcrypt-bctool-gain-privileges(6648) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |