Vulnerabilities > CVE-2000-0703 - Unspecified vulnerability in Larry Wall Perl

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
larry-wall
exploit available

Summary

suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence.

Vulnerable Configurations

Part Description Count
Application
Larry_Wall
4

Exploit-Db

  • descriptionSuidperl 5.00503 Mail Shell Escape Vulnerability (1). CVE-2000-0703. Local exploit for linux platform
    idEDB-ID:20141
    last seen2016-02-02
    modified2000-08-07
    published2000-08-07
    reporterSebastian Krahmer
    sourcehttps://www.exploit-db.com/download/20141/
    titleSuidperl 5.00503 Mail Shell Escape Vulnerability 1
  • descriptionSuidperl 5.00503 Mail Shell Escape Vulnerability (2). CVE-2000-0703. Local exploit for linux platform
    idEDB-ID:20142
    last seen2016-02-02
    modified2000-08-07
    published2000-08-07
    reporterMichal Zalewski
    sourcehttps://www.exploit-db.com/download/20142/
    titleSuidperl 5.00503 Mail Shell Escape Vulnerability 2

Redhat

advisories
rhsa
idRHSA-2000:048