Vulnerabilities > CVE-2001-0873 - Unspecified vulnerability in IAN Lance Taylor Uucp 1.0.6

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
ian-lance-taylor
nessus
exploit available

Summary

uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option.

Vulnerable Configurations

Part Description Count
Application
Ian_Lance_Taylor
1

Exploit-Db

descriptionTaylor UUCP 1.0.6 Argument Handling Privilege Elevation Vulnerability. CVE-2001-0873. Local exploit for unix platform
idEDB-ID:21106
last seen2016-02-02
modified2001-09-08
published2001-09-08
reporterzen-parse
sourcehttps://www.exploit-db.com/download/21106/
titleTaylor UUCP 1.0.6 - Argument Handling Privilege Elevation Vulnerability

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-079.NASL
descriptionZenith Parsec discovered a security hole in Taylor UUCP 1.06.1. It permits a local user to copy any file to anywhere which is writable by the uucp uid, which effectively means that a local user can completely subvert the UUCP subsystem, including stealing mail, etc. If a remote user with UUCP access is able to create files on the local system, and can successfully make certain guesses about the local directory structure layout, then the remote user can also subvert the UUCP system. A default installation of UUCP will permit a remote user to create files on the local system if the UUCP public directory has been created with world write permissions. Obviously this security hole is serious for anybody who uses UUCP on a multi-user system with untrusted users, or anybody who uses UUCP and permits connections from untrusted remote systems. It was thought that this problem has been fixed with DSA 079-1, but that didn
last seen2020-06-01
modified2020-06-02
plugin id14916
published2004-09-29
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/14916
titleDebian DSA-079-2 : uucp - uucp uid/gid access

Redhat

advisories
rhsa
idRHSA-2001:165