Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2000-0703

Опубликовано: 20 окт. 2000
Источник: nvd
CVSS2: 7.2
EPSS Низкий

Описание

suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:larry_wall:perl:5.4.5:*:*:*:*:*:*:*
cpe:2.3:a:larry_wall:perl:5.5:*:*:*:*:*:*:*
cpe:2.3:a:larry_wall:perl:5.5.3:*:*:*:*:*:*:*
cpe:2.3:a:larry_wall:perl:5.6:*:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00307
Низкий

7.2 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

redhat
почти 25 лет назад

suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence.

github
около 3 лет назад

suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence.

EPSS

Процентиль: 53%
0.00307
Низкий

7.2 High

CVSS2

Дефекты

NVD-CWE-Other