Vulnerabilities > CVE-2000-1103 - Unspecified vulnerability in Bsdi BSD OS

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
bsdi
exploit available

Summary

rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.

Vulnerable Configurations

Part Description Count
OS
Bsdi
4

Exploit-Db

descriptionBSDi 3.0 / 4.0 rcvtty[mh] Local Exploit. CVE-2000-1103. Local exploit for bsd platform
idEDB-ID:202
last seen2016-01-31
modified2000-11-21
published2000-11-21
reportervade79
sourcehttps://www.exploit-db.com/download/202/
titleBSDi 3.0 / 4.0 - rcvttymh Local Exploit