CVE-2000-1073: High severity Netscape Iplanet Ical vulnerability
csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2000-1073?
CVE-2000-1073 has a severity rating that indicates it can allow local users to gain root privileges, which is considered critical.
How do I fix CVE-2000-1073?
To fix CVE-2000-1073, update to a newer version of iCal that does not contain this vulnerability or restrict access to the csstart program.
Who is affected by CVE-2000-1073?
CVE-2000-1073 affects users of Netscape iPlanet iCal version 2.1 Patch 2.
What kind of attack does CVE-2000-1073 enable?
CVE-2000-1073 enables local users to perform a privilege escalation attack by creating a malicious cshttpd program.
Is CVE-2000-1073 a remote or local vulnerability?
CVE-2000-1073 is a local vulnerability, as it requires an attacker to have local access to the system.