CVE-2001-1029
Last modified
CVE-2001-1029 is a vulnerability of currently unknown severity. libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openssh | 4.5 |
| Freebsd | Freebsd | <= 4.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1029?
How severe is CVE-2001-1029?
How do I fix CVE-2001-1029?
Are you affected by CVE-2001-1029?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
