CVE-2001-0195: High severity Debian Debian Linux vulnerability
Published Mar 26, 2001
·Updated
sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.
Affected Software
1 affected component
Debian Debian Linux=2.2
Remediation
Patch Available
Event History
Mar 26, 2001
CVE Published
via NVD·05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0195?
CVE-2001-0195 is classified as a high-severity vulnerability due to the risk of privilege escalation via world-readable /etc/shadow.
2
How do I fix CVE-2001-0195?
To fix CVE-2001-0195, upgrade to sash version 3.4-4 or later in your Debian installation.
3
Who is affected by CVE-2001-0195?
CVE-2001-0195 affects Debian GNU/Linux 2.2 systems using sash versions prior to 3.4-4.
4
What can attackers do with CVE-2001-0195?
With CVE-2001-0195, local attackers can potentially read sensitive password hashes from /etc/shadow to perform password cracking.
5
When was CVE-2001-0195 reported?
CVE-2001-0195 was reported in the year 2001, highlighting a significant security flaw in earlier Debian systems.