CVE-2000-0018: High severity WindowMaker Wmmon vulnerability
wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
wmmon (WindowMaker)from your environment.Uninstall or remove wmmon if it is not required on the system.
- Configuration
Ensure any .wmmonrc configuration files are owned by the intended user and are not writable by other local users; configure permissions so only the owner can modify the file.
wmmon (WindowMaker) .wmmonrc file permissions = restrict write access to the file owner only - Compensating control
Limit which local accounts can run or access wmmon (for example via local account policies, sudo rules, or file ACLs) and restrict access to directories where .wmmonrc files may reside.
- Operational
Audit existing .wmmonrc files for unauthorized or malicious content and remediate or replace any compromised configuration files.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0018?
CVE-2000-0018 is classified as a moderate severity vulnerability that allows local users to gain elevated privileges.
How do I fix CVE-2000-0018?
To mitigate CVE-2000-0018, ensure that the .wmmonrc configuration file has proper permissions to prevent unauthorized access.
Who is affected by CVE-2000-0018?
CVE-2000-0018 affects local users of FreeBSD systems running wmmon version 1.0b2.
What type of vulnerability is CVE-2000-0018?
CVE-2000-0018 is a privilege escalation vulnerability related to insecure configuration file permissions.
Is CVE-2000-0018 specific to a software version?
Yes, CVE-2000-0018 specifically affects version 1.0b2 of wmmon from WindowMaker.