CVE-2000-0506
Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/06/2000
Last modified:
07/11/2023
Description
The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability."
Impact
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:2.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.0.30:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.0.33:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.0.34:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.0.35:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.0.36:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.0.37:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.0.38:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.2.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.2.10:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.2.12:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.2.13:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.2.14:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:2.2.15:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- ftp://sgigate.sgi.com/security/20000802-01-P
- http://archives.neohapsis.com/archives/bugtraq/2000-06/0062.html
- http://archives.neohapsis.com/archives/bugtraq/2000-06/0063.html
- http://www.redhat.com/support/errata/RHSA-2000-037.html
- http://www.securityfocus.com/bid/1322
- http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.21.0006090852340.3475-300000%40alfa.elzabsoft.pl