Vulnerabilities > CVE-2001-1345 - Unspecified vulnerability in Jetico Bestcrypt
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-06/0005.html
- http://archives.neohapsis.com/archives/bugtraq/2001-06/0005.html
- http://www.jetico.com/index.htm#/linux.htm
- http://www.jetico.com/index.htm#/linux.htm
- http://www.securityfocus.com/bid/2820
- http://www.securityfocus.com/bid/2820
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6648
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6648