4.6
CVSSv2

CVE-2000-0035

Published: 28/12/1999 Updated: 18/10/2016
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

resend command in Majordomo allows local users to gain privileges via shell metacharacters.

Vulnerable Product Search on Vulmon Subscribe to Product

great circle associates majordomo

Exploits

source: wwwsecurityfocuscom/bid/902/info It is possible to execute arbitrary commands with elevated privileges through exploiting the majordomo binary, "resend" A setuid root wrapper program calls resend after setuid()ing and setgid()ing to lowered (but still elevated) privileges which it runs resend with resend contains a call to open( ...