Vulnerabilities > CVE-2001-1324 - Unspecified vulnerability in Paul Jarc Idtools 20010531/20010608

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
paul-jarc

Summary

cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.

Vulnerable Configurations

Part Description Count
Application
Paul_Jarc
2