HIGH · 7.2

CVE-2001-0424

BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

Vulnerability Description

BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
TimecopBubblemon1.0
FreebsdFreebsd6.2

References

FAQ

What is CVE-2001-0424?

CVE-2001-0424 is a vulnerability with a CVSS score of 7.2 (HIGH). BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

How severe is CVE-2001-0424?

CVE-2001-0424 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2001-0424?

Check the references section above for vendor advisories and patch information. Affected products include: Timecop Bubblemon, Freebsd Freebsd.