CVE-2001-1029
Last modified
CVE-2001-1029 is a vulnerability of currently unknown severity. libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openssh | 4.5 |
| Freebsd | Freebsd | <= 4.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1029?
How severe is CVE-2001-1029?
How do I fix CVE-2001-1029?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2001
- CVE-2001-1023Xcache 2.1 allows remote attackers to determine the absolute…
- CVE-2001-1024login.gas.bat and other CGI scripts in Entrust getAccess all…
- CVE-2001-1025PHP-Nuke 5.x allows remote attackers to perform arbitrary SQ…
- CVE-2001-1026Trend Micro InterScan AppletTrap 2.0 does not properly filte…
- CVE-2001-1027Buffer overflow in WindowMaker (aka wmaker) 0.64 and earlier…
- CVE-2001-1028Buffer overflow in ultimate_source function of man 1.5 and e…
- CVE-2001-1030Squid before 2.3STABLE5 in HTTP accelerator mode does not en…
- CVE-2001-1031Directory traversal vulnerability in Meteor FTP 1.0 allows r…
- CVE-2001-1032admin.php in PHP-Nuke 5.2 and earlier, except 5.0RC1, does n…
- CVE-2001-1033Compaq TruCluster 1.5 allows remote attackers to cause a den…
- CVE-2001-1034Format string vulnerability in Hylafax on FreeBSD allows loc…
- CVE-2001-1035Binary decoding feature of slrn 0.9 and earlier allows remot…
Are you affected by CVE-2001-1029?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
