CVE-2000-0378
Last modified
CVE-2000-0378 is a vulnerability of currently unknown severity. The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.. EPSS estimates a 1.08% chance of exploitation in the next 30 days.
Description
The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Linux | 6.0 |
| Redhat | Linux | 6.1 |
| Redhat | Linux | 6.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2000-0378?
How severe is CVE-2000-0378?
How do I fix CVE-2000-0378?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2000
- CVE-2000-0372Vulnerability in Caldera rmt command in the dump package 0.4…
- CVE-2000-0373Vulnerabilities in the KDE kvt terminal program allow local …
- CVE-2000-0374The default configuration of kdm in Caldera and Mandrake Lin…
- CVE-2000-0375The kernel in FreeBSD 3.2 follows symbolic links when it cre…
- CVE-2000-0376Buffer overflow in the HTTP proxy server for the i-drive Fil…
- CVE-2000-0377The Remote Registry server in Windows NT 4.0 allows local au…
- CVE-2000-0379The Netopia R9100 router does not prevent authenticated user…
- CVE-2000-0380The IOS HTTP service in Cisco routers and switches running I…
- CVE-2000-0381The Gossamer Threads DBMan db.cgi CGI script allows remote a…
- CVE-2000-0382ColdFusion ClusterCATS appends stale query string arguments …
- CVE-2000-0383The file transfer component of AOL Instant Messenger (AIM) r…
- CVE-2000-0384NetStructure 7110 and 7180 have undocumented accounts (servn…
Are you affected by CVE-2000-0378?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
