← Back

CVE-2001-0424

nvd nist
Published: Jul 2, 2001Modified: Apr 16, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

Affected (26)

1 product
Bubblemon
1 product
Freebsd
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Timecop
Version 1.0
Version 1.0pl1
Version 1.0pl2
Version 1.0pl3
Version 1.0pl4
Version 1.0pl6
Version 1.0pl7
Version 1.0pl8
Version 1.0pl9
Version 1.1
Version 1.1test1
Version 1.1test2
Version 1.1test3
Version 1.1test4
Version 1.1test5
Version 1.1test6
Version 1.1test7
Version 1.21
Version 1.21test1
Version 1.22
Version 1.23
Version 1.2
Version 1.2test1
Version 1.31
Version 1.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.2 stable

References (4)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.