CVE-2001-0905Signal Handler Race Condition in Procmail

Severity
6.2MEDIUMNVD
EPSS
0.0%
top 85.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 18
Latest updateMay 3

Description

Race condition in signal handling of procmail 3.20 and earlier, when running setuid, allows local users to cause a denial of service or gain root privileges by sending a signal while a signal handling routine is already running.

CVSS vector

AV:L/AC:H/C:C/I:C/A:CExploitability: 1.9 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-gjq2-7fjr-x6vv: Race condition in signal handling of procmail 32022-05-03

📋Vendor Advisories

1
Red Hat
security flaw2001-07-03

📐Framework References

1
CWE
Signal Handler Race Condition

💬Community

1
Bugzilla
CVE-2001-0905 security flaw2018-08-16