CVE-2000-0163: Medium severity freebsd freebsd vulnerability
asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
FreeBSD: asmon and ascpufrom your environment.If asmon and/or ascpu are not required, uninstall or disable these utilities to prevent local users from exploiting the configuration file to gain root privileges.
- Configuration
Ensure the configuration file used by asmon and ascpu is owned by root and writable only by root; remove write permissions for unprivileged local users (e.g., set ownership to root and revoke group/other write access).
FreeBSD asmon/ascpu configuration file configuration file ownership/permissions = restrict write access to root only
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0163?
CVE-2000-0163 has a severity rating of high due to its potential for local users to gain root privileges.
How do I fix CVE-2000-0163?
To fix CVE-2000-0163, ensure that the configuration files for asmon and ascpu have correct permissions and implement security patches provided by FreeBSD.
Which versions of FreeBSD are affected by CVE-2000-0163?
CVE-2000-0163 affects FreeBSD versions 3.0 through 3.4.
Can CVE-2000-0163 be exploited remotely?
CVE-2000-0163 cannot be exploited remotely as it requires local user access to the system.
What components are involved in CVE-2000-0163?
CVE-2000-0163 specifically involves the asmon and ascpu components of FreeBSD.