First published: Mon Dec 11 2000(Updated: )
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Iplanet Ical | =2.1-patch2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1074 is considered a high-severity vulnerability due to potential root privilege escalation.
To fix CVE-2000-1074, ensure that you upgrade to a version of iCal that does not utilize relative pathnames for library installations.
CVE-2000-1074 specifically affects Netscape iPlanet iCal version 2.1 Patch 2.
CVE-2000-1074 is a local vulnerability that requires access to the affected system to exploit.
The potential consequence of CVE-2000-1074 includes unauthorized root access to the system via Trojan Horse libraries.