Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2000-0231Linux vulnerability

6 documents4 sources
Severity
7.2HIGHNVD
EPSS
0.1%
top 64.75%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 16
Latest updateApr 30

Description

Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

NVDsuse/suse_linux4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-3p9r-9j6c-6wxp: Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges2022-04-30
CVEList
CVE-2000-0231: Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges2000-06-02

💥Exploits & PoCs

3
Exploit-DB
Microsoft SQL Server 7.0/2000 / MSDE - Named Pipe Denial of Service (MS03-031)2003-07-23
Exploit-DB
MIRC 2.x/3.x/4.x/5.x - Nick Buffer Overflow2002-02-03
Exploit-DB
Halloween Linux 4.0 / SuSE Linux 6.0/6.1/6.2/6.3 - 'kreatecd' Local Privilege Escalation2000-03-16
CVE-2000-0231 — Halloween Linux vulnerability | cvebase