First published: Mon Dec 11 2000(Updated: )
csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Iplanet Ical | =2.1-patch2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1073 has a severity rating that indicates it can allow local users to gain root privileges, which is considered critical.
To fix CVE-2000-1073, update to a newer version of iCal that does not contain this vulnerability or restrict access to the csstart program.
CVE-2000-1073 affects users of Netscape iPlanet iCal version 2.1 Patch 2.
CVE-2000-1073 enables local users to perform a privilege escalation attack by creating a malicious cshttpd program.
CVE-2000-1073 is a local vulnerability, as it requires an attacker to have local access to the system.