CVE-2001-1017: High severity FreeBSD FreeBSD vulnerability
rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file while rmuser is running, obtain the password hashes, and crack the passwords.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1017?
CVE-2001-1017 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2001-1017?
To remediate CVE-2001-1017, ensure that the rmuser utility does not create world-readable copies of sensitive files during execution.
Who is affected by CVE-2001-1017?
CVE-2001-1017 affects users of FreeBSD versions 4.2 and 4.3.
What can attackers do with CVE-2001-1017?
Attackers can exploit CVE-2001-1017 to read hashed passwords from the copied master.passwd file, potentially allowing them to crack user passwords.
When was CVE-2001-1017 discovered?
CVE-2001-1017 was disclosed in 2001 and relates to vulnerabilities present in older versions of FreeBSD.