7.2
CVSSv2

CVE-2000-0171

Published: 11/03/2000 Updated: 10/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

atsadc in the atsar package for Linux does not properly check the permissions of an output file, which allows local users to gain root privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

at computing atsar linux 1.4

Exploits

source: wwwsecurityfocuscom/bid/1048/info atsar is a linux load monitoring software package released under the GPL by AT Computing atsadc is a setuid root binary that is included in the atsar package atsadc is setuid because it obtains informatin via /dev/kmem atsadc will accept as an argument an output file, which it will open -- with ...