CVE-2000-0052
published 2000-01-04CVE-2000-0052: Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.
PriorityP421high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
0.89%
55.3th percentile
Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| turbolinux | turbolinux | — | — |
| turbolinux | turbolinux | — | — |
| turbolinux | turbolinux | — | — |
| turbolinux | turbolinux | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2000-01-04·CVSS 7.2
CVE-2000-0052 [HIGH] security flaw
security flaw
Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.
Statement: This issue was fixed in the following products:
- Red Hat Linux 6.0 - RHSA-2000:001 (2000-01-04)
- Red Hat Linux 6.1 - RHSA-2000:001 (2000-01-04)
GHSA
GHSA-cxvc-f794-62r9: Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a
ghsa_unreviewed·2022-04-30
CVE-2000-0052 [HIGH] GHSA-cxvc-f794-62r9: Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a
Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.
No detection rules found.
Exploit-DB
Mandrake 6.x / RedHat 6.x / Turbolinux 3.5 b2/4.x/6.0.2 userhelper/PAM - Path (2)
exploitdb·2000-03-15
CVE-2000-0052 Mandrake 6.x / RedHat 6.x / Turbolinux 3.5 b2/4.x/6.0.2 userhelper/PAM - Path (2)
Mandrake 6.x / RedHat 6.x / Turbolinux 3.5 b2/4.x/6.0.2 userhelper/PAM - Path (2)
---
// source: https://www.securityfocus.com/bid/913/info
Because of double path vulnerabilities in the binary userhelper and PAM, it is possible to get root locally on RedHat 6.0 and 6.1 systems. Both userhelper and PAM follow ".." paths and userhelper allows you to specifiy a program to execute as an argument to the -w parameter (which is expected to have an entry in /etc/security/console.apps). Because of this, it's possible to specifiy a program such as "../../../tmp/myprog", which would (to userhelper) be "/etc/security/console.apps/../../../tmp/myprog". If "myprog" exists, PAM will then try to execute it (with the same filename). PAM first does a check to see if the configuration file for "../../../t
Exploit-DB
Mandrake 6.x / RedHat 6.x / Turbolinux 3.5 b2/4.x/6.0.2 userhelper/PAM - Path (1)
exploitdb·2000-01-04
CVE-2000-0052 Mandrake 6.x / RedHat 6.x / Turbolinux 3.5 b2/4.x/6.0.2 userhelper/PAM - Path (1)
Mandrake 6.x / RedHat 6.x / Turbolinux 3.5 b2/4.x/6.0.2 userhelper/PAM - Path (1)
---
Mandrake 6.0/6.1,RedHat 6.0/6.1,Turbolinux 3.5 b2/4.2/4.4/6.0.2 userhelper/PAM Path Vulnerability (1)
source: https://www.securityfocus.com/bid/913/info
Because of double path vulnerabilities in the binary userhelper and PAM, it is possible to get root locally on RedHat 6.0 and 6.1 systems. Both userhelper and PAM follow ".." paths and userhelper allows you to specifiy a program to execute as an argument to the -w parameter (which is expected to have an entry in /etc/security/console.apps). Because of this, it's possible to specifiy a program such as "../../../tmp/myprog", which would (to userhelper) be "/etc/security/console.apps/../../../tmp/myprog". If "myprog" exists, PAM will then try to execute
http://www.l0pht.com/advisories/pam_advisoryhttp://www.redhat.com/support/errata/RHSA-2000-001.htmlhttp://www.securityfocus.com/bid/913http://xforce.iss.net/search.php3?type=2&pattern=linux-pam-userhelperhttp://www.l0pht.com/advisories/pam_advisoryhttp://www.redhat.com/support/errata/RHSA-2000-001.htmlhttp://www.securityfocus.com/bid/913http://xforce.iss.net/search.php3?type=2&pattern=linux-pam-userhelper
2000-01-04
Published