CVE-2001-0905: Race Condition
Published Oct 18, 2001
·Updated
Race condition in signal handling of procmail 3.20 and earlier, when running setuid, allows local users to cause a denial of service or gain root privileges by sending a signal while a signal handling routine is already running.
Affected Software
1 affected component
procmail procmail<=3.20
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 18, 2001
CVE Published
04:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0905?
CVE-2001-0905 is classified as a high severity vulnerability due to its potential for local users to gain root privileges.
2
How do I fix CVE-2001-0905?
To fix CVE-2001-0905, upgrade to procmail version 3.21 or later, which addresses this race condition.
3
What impact does CVE-2001-0905 have?
CVE-2001-0905 can allow a local user to cause a denial of service or escalate privileges to root.
4
In which versions of procmail is CVE-2001-0905 present?
CVE-2001-0905 is present in procmail versions 3.20 and earlier.
5
Who is affected by CVE-2001-0905?
Local users of systems running vulnerable versions of procmail with setuid permissions are affected by CVE-2001-0905.