CVE-2000-1103: High severity BSDI Bsd Os vulnerability
Published Dec 19, 2000
·Updated
rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.
Affected Software
4 affected components
BSDI Bsd Os=4.0.1
BSDI Bsd Os=3.1
BSDI Bsd Os=3.0
BSDI Bsd Os=4.0
Event History
Dec 19, 2000
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1103?
CVE-2000-1103 is considered to have a high severity as it allows local attackers to gain elevated privileges.
2
How do I fix CVE-2000-1103?
To fix CVE-2000-1103, ensure that rcvtty correctly drops privileges before executing any scripts.
3
What versions of BSD are affected by CVE-2000-1103?
CVE-2000-1103 affects BSD versions 3.0, 3.1, 4.0, and 4.0.1.
4
Can a local attacker exploit CVE-2000-1103?
Yes, a local attacker can exploit CVE-2000-1103 by specifying a Trojan horse script on the command line.
5
Is CVE-2000-1103 a remote vulnerability?
No, CVE-2000-1103 is a local vulnerability that requires system access to exploit.