CVE-2001-0196: Medium severity FreeBSD FreeBSD vulnerability
Published May 3, 2001
·Updated
inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group.
Affected Software
4 affected components
FreeBSD FreeBSD=3.5.1
FreeBSD FreeBSD=4.2
FreeBSD FreeBSD=4.1.1
FreeBSD FreeBSD=3.5
Remediation
Patch Available
Event History
May 3, 2001
CVE Published
04:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0196?
CVE-2001-0196 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to sensitive file information.
2
How do I fix CVE-2001-0196?
To fix CVE-2001-0196, upgrade to a version of FreeBSD that does not include the vulnerable inetd ident server.
3
What versions of FreeBSD are affected by CVE-2001-0196?
CVE-2001-0196 affects FreeBSD 3.5, 3.5.1, 4.1.1, and 4.2.
4
What risk does CVE-2001-0196 pose to my system?
CVE-2001-0196 allows remote attackers to read the first 16 bytes of files accessible by the wheel group, which may expose sensitive data.
5
Is CVE-2001-0196 exploitable remotely?
Yes, CVE-2001-0196 can be exploited remotely by attackers targeting the inetd ident service.