CVE-2001-1374

CWE-3056 documents6 sources
Severity
7.2HIGH
EPSS
0.1%
top 83.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateApr 30

Description

expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages3 packages

NVDdon_libes/expect37 versions+36
NVDredhat/linux7.0
NVDconectiva/linux6.0, 7.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xp42-65qj-mvgv: expect before 52022-04-30
CVEList
CVE-2001-1374: expect before 52003-04-02

📋Vendor Advisories

1
Red Hat
security flaw2001-02-18

📐Framework References

1
CWE
Authentication Bypass by Primary Weakness

💬Community

1
Bugzilla
CVE-2001-1374 security flaw2018-08-16
CVE-2001-1374 (HIGH CVSS 7.2) | expect before 5.32 searches for its | cvebase.io