CVE-2000-0018: High severity WindowMaker Wmmon vulnerability

Published Dec 22, 1999
·
Updated

wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.

Affected Software

1 affected component
WindowMaker Wmmon=1.0b2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove wmmon (WindowMaker) from your environment.

    Uninstall or remove wmmon if it is not required on the system.

  2. Configuration

    Ensure any .wmmonrc configuration files are owned by the intended user and are not writable by other local users; configure permissions so only the owner can modify the file.

    wmmon (WindowMaker) .wmmonrc file permissions = restrict write access to the file owner only
  3. Compensating control

    Limit which local accounts can run or access wmmon (for example via local account policies, sudo rules, or file ACLs) and restrict access to directories where .wmmonrc files may reside.

  4. Operational

    Audit existing .wmmonrc files for unauthorized or malicious content and remediate or replace any compromised configuration files.

Event History

Dec 22, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jul 12, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0018?

CVE-2000-0018 is classified as a moderate severity vulnerability that allows local users to gain elevated privileges.

2

How do I fix CVE-2000-0018?

To mitigate CVE-2000-0018, ensure that the .wmmonrc configuration file has proper permissions to prevent unauthorized access.

3

Who is affected by CVE-2000-0018?

CVE-2000-0018 affects local users of FreeBSD systems running wmmon version 1.0b2.

4

What type of vulnerability is CVE-2000-0018?

CVE-2000-0018 is a privilege escalation vulnerability related to insecure configuration file permissions.

5

Is CVE-2000-0018 specific to a software version?

Yes, CVE-2000-0018 specifically affects version 1.0b2 of wmmon from WindowMaker.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203