First published: Tue Jan 04 2000(Updated: )
Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Linux | =6.0 | |
Turbolinux | =4.4 | |
Turbolinux | =4.2 | |
Turbolinux | =6.0.2 | |
Mandrake Linux | =6.0 | |
Red Hat Linux | =6.1 | |
Turbolinux | =3.5b2 | |
Mandrake Linux | =6.1 | |
=6.0 | ||
=6.1 | ||
=6.0 | ||
=6.1 | ||
=3.5b2 | ||
=4.2 | ||
=4.4 | ||
=6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0052 is considered a high-severity vulnerability as it allows local users to gain root access.
To fix CVE-2000-0052, update the usermode package to the latest version provided by your distribution.
CVE-2000-0052 affects Red Hat Linux versions 6.0 and 6.1, as well as Mandrake and Turbolinux versions mentioned in the vulnerability details.
CVE-2000-0052 involves a 'dot dot' attack that exploits improper handling of file paths in the userhelper program.
Yes, since it allows privilege escalation, CVE-2000-0052 could be exploited by local attackers in a vulnerable environment.