Back

HIGH

security flaw

Published Oct 13, 2000

Description

suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence.

Affected products

Remediation

Red Hat statement

This issue was fixed in the following products: - Red Hat Linux 5.0 - RHSA-2000:048 (2000-08-07) - Red Hat Linux 5.1 - RHSA-2000:048 (2000-08-07) - Red Hat Linux 5.2 - RHSA-2000:048 (2000-08-07) - Red Hat Linux 6.0 - RHSA-2000:048 (2000-08-07) - Red Hat Linux 6.1 - RHSA-2000:048 (2000-08-07) - Red Hat Linux 6.2 - RHSA-2000:048 (2000-08-07)

Metrics

Weaknesses (0)

No CWE recorded.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 13, 2000
Updated Aug 8, 2024
Reserved Sep 19, 2000
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Aug 7, 2000