First published: Wed Jul 05 2000(Updated: )
libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =3.1 | |
FreeBSD Kernel | =3.0 | |
FreeBSD Kernel | =3.2 | |
FreeBSD Kernel | =3.3 | |
FreeBSD Kernel | =4.0 | |
FreeBSD Kernel | =3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0595 is classified as a local privilege escalation vulnerability.
To fix CVE-2000-0595, ensure that .editrc files are only allowed in the user's home directory and prevent unauthorized access to other directories.
CVE-2000-0595 affects local users of FreeBSD versions 3.0 through 4.0.
CVE-2000-0595 allows local users to execute arbitrary commands, leading to potential system compromise.
No, CVE-2000-0595 is not a remote access vulnerability; it requires local access to exploit.