Vulnerabilities > CVE-2001-1180 - Unspecified vulnerability in Freebsd
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
FreeBSD 4.3 does not properly clear shared signal handlers when executing a process, which allows local users to gain privileges by calling rfork with a shared signal handler, having the child process execute a setuid program, and sending a signal to the child.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 4 |
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:42.signal.v1.1.asc
- http://archives.neohapsis.com/archives/bugtraq/2001-07/0179.html
- http://ciac.llnl.gov/ciac/bulletins/l-111.shtml
- http://www.kb.cert.org/vuls/id/943633
- http://www.osvdb.org/1897
- http://www.securityfocus.com/bid/3007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6829