MEDIUM · 4.6

CVE-2001-1324

cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID ...

Vulnerability Description

cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Paul JarcIdtools2001-05-31

References

FAQ

What is CVE-2001-1324?

CVE-2001-1324 is a vulnerability with a CVSS score of 4.6 (MEDIUM). cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID ...

How severe is CVE-2001-1324?

CVE-2001-1324 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2001-1324?

Check the references section above for vendor advisories and patch information. Affected products include: Paul Jarc Idtools.