First published: Sat Dec 25 1999(Updated: )
strace allows local users to read arbitrary files via memory mapped file names.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
strace | ||
Linux kernel | =2.3.20 | |
Linux Kernel | =2.3.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0006 is considered a moderate severity vulnerability due to its potential for unauthorized access to sensitive files.
To fix CVE-2000-0006, update strace to a version that addresses this vulnerability or implement access controls to limit file access.
Local users on systems running vulnerable versions of strace or Linux kernel 2.3.20 are at risk from CVE-2000-0006.
CVE-2000-0006 allows local users to read arbitrary files through the use of memory mapped file names.
While CVE-2000-0006 was reported in the year 2000, its relevance depends on whether vulnerable software versions are still in use.