CVE-2001-1374
published 2001-07-19CVE-2001-1374: expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse…
PriorityP421high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.37%
29.5th percentile
expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
| don_libes | expect | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2001-02-18·CVSS 7.2
CVE-2001-1374 [HIGH] security flaw
security flaw
expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.
GHSA
GHSA-xp42-65qj-mvgv: expect before 5
ghsa_unreviewed·2022-04-30
CVE-2001-1374 [HIGH] GHSA-xp42-65qj-mvgv: expect before 5
expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.
No detection rules found.
No public exploits indexed.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000409http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:060http://www.redhat.com/support/errata/RHSA-2002-148.htmlhttp://www.securityfocus.com/bid/3074https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=22187https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=28224https://exchange.xforce.ibmcloud.com/vulnerabilities/6870http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000409http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:060http://www.redhat.com/support/errata/RHSA-2002-148.htmlhttp://www.securityfocus.com/bid/3074https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=22187https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=28224https://exchange.xforce.ibmcloud.com/vulnerabilities/6870
2001-07-19
Published