Vulnerabilities > CVE-2002-0767 - Unspecified vulnerability in Richard Gooch Simpleinit 2.0.2

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
richard-gooch
exploit available

Summary

simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause simpleinit to execute arbitrary programs with root privileges.

Vulnerable Configurations

Part Description Count
Application
Richard_Gooch
1

Exploit-Db

descriptionRichard Gooch SimpleInit 2.0.2 Open File Descriptor Vulnerability. CVE-2002-0767. Local exploit for linux platform
idEDB-ID:21538
last seen2016-02-02
modified2002-06-12
published2002-06-12
reporterPatrick Smith
sourcehttps://www.exploit-db.com/download/21538/
titleRichard Gooch SimpleInit 2.0.2 Open File Descriptor Vulnerability