CVE-2001-1029
LOW 2.1EPSS 1.4%
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.
- CVSS v2.0
- 2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 1.37% chance of exploitation in the next 30 days, 70th percentile
- Published
- 2004-09-01
- Updated
- 2024-08-08