Vulnerability Description
BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Timecop | Bubblemon | 1.0 |
| Freebsd | Freebsd | 6.2 |
References
- http://marc.info/?l=bugtraq&m=98744422105430&w=2
- http://www.securityfocus.com/bid/2609PatchVendor Advisory
- http://marc.info/?l=bugtraq&m=98744422105430&w=2
- http://www.securityfocus.com/bid/2609PatchVendor Advisory
FAQ
What is CVE-2001-0424?
CVE-2001-0424 is a vulnerability with a CVSS score of 7.2 (HIGH). BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.
How severe is CVE-2001-0424?
CVE-2001-0424 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0424?
Check the references section above for vendor advisories and patch information. Affected products include: Timecop Bubblemon, Freebsd Freebsd.