CVE-2001-0823: High severity SGI Performance Co-pilot vulnerability
Published Dec 6, 2001
·Updated
The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCPLOGDIR).
Affected Software
12 affected components
SGI Performance Co-pilot=2.1.7
SGI Performance Co-pilot=2.1.9
SGI Performance Co-pilot=2.1.10
SGI Performance Co-pilot=2.1.11
SGI Performance Co-pilot=2.2
SGI Performance Co-pilot=2.1.3
SGI Performance Co-pilot=2.1.5
SGI Performance Co-pilot=2.1.2
SGI Performance Co-pilot=2.1.6
SGI Performance Co-pilot=2.1.8
SGI Performance Co-pilot=2.1.1
SGI Performance Co-pilot=2.1.4
Remediation
Patch Available
Event History
Dec 6, 2001
CVE Published
05:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0823?
CVE-2001-0823 has a moderate severity rating due to the potential for local privilege escalation.
2
How do I fix CVE-2001-0823?
To fix CVE-2001-0823, update Performance Co-Pilot to version 2.2.1-3 or later.
3
What versions of Performance Co-Pilot are affected by CVE-2001-0823?
CVE-2001-0823 affects Performance Co-Pilot versions 2.1.1 through 2.2.0.
4
What type of vulnerability is CVE-2001-0823?
CVE-2001-0823 is a local privilege escalation vulnerability due to a symlink attack.
5
Who is affected by CVE-2001-0823?
Local users on systems running vulnerable versions of Performance Co-Pilot are affected by CVE-2001-0823.