CVE-2001-1180: High severity FreeBSD FreeBSD vulnerability
Published Jul 10, 2001
·Updated
FreeBSD 4.3 does not properly clear shared signal handlers when executing a process, which allows local users to gain privileges by calling rfork with a shared signal handler, having the child process execute a setuid program, and sending a signal to the child.
Affected Software
4 affected components
FreeBSD FreeBSD=4.1
FreeBSD FreeBSD=4.2
FreeBSD FreeBSD=4.0
FreeBSD FreeBSD=4.3
Remediation
Patch Available
Patch Available
Event History
Jul 10, 2001
CVE Published
04:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1180?
CVE-2001-1180 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2001-1180?
To fix CVE-2001-1180, you should update your FreeBSD system to a version higher than 4.3 that has addressed this vulnerability.
3
What versions of FreeBSD are affected by CVE-2001-1180?
CVE-2001-1180 affects FreeBSD versions 4.0, 4.1, 4.2, and 4.3.
4
Can CVE-2001-1180 be exploited remotely?
No, CVE-2001-1180 requires local access for exploitation.
5
What is the impact of successfully exploiting CVE-2001-1180?
The impact of exploiting CVE-2001-1180 allows local users to gain elevated privileges through a setuid program.