Vulnerabilities > CVE-2001-0912 - Local Security vulnerability in Mandrakesoft Mandrake Linux 8.1

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
mandrakesoft
nessus

Summary

Packaging error for expect 8.3.3 in Mandrake Linux 8.1 causes expect to search for its libraries in the /home/snailtalk directory before other directories, which could allow a local user to gain root privileges.

Vulnerable Configurations

Part Description Count
OS
Mandrakesoft
1

Nessus

NASL familyMandriva Local Security Checks
NASL idMANDRAKE_MDKSA-2001-087.NASL
descriptionA packaging problem that can lead to a root compromise existed in the expect package as provided in Mandrake Linux 8.1. expect would look for libraries in the directory /home/snailtalk/tmp/tcltk-root/usr/lib before any other and if such a user existed on the system, with rogue libraries, if root were to execute expect, a compromise could occur.
last seen2020-06-01
modified2020-06-02
plugin id13900
published2004-07-31
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/13900
titleMandrake Linux Security Advisory : expect (MDKSA-2001:087)