7.2
CVSSv2

CVE-2002-0767

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause simpleinit to execute arbitrary programs with root privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

richard gooch simpleinit 2.0.2

Exploits

source: wwwsecurityfocuscom/bid/5001/info A vulnerability has been reported for simpleinit that may allow users to execute arbitrary commands as the superuser The vulnerability occurs because simpleinit may allow some child processes to inherit a file descriptor with read-write access The file descriptor is used to access /dev/initctl ...