Vulnerability Details CVE-2001-1374
expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.5%
CVSS Severity
CVSS v2 Score 7.2
Products affected by CVE-2001-1374
-
cpe:2.3:a:don_libes:expect:0
-
cpe:2.3:a:don_libes:expect:1
-
cpe:2.3:a:don_libes:expect:2
-
cpe:2.3:a:don_libes:expect:3
-
cpe:2.3:a:don_libes:expect:4
-
cpe:2.3:a:don_libes:expect:5.0
-
cpe:2.3:a:don_libes:expect:5.1
-
cpe:2.3:a:don_libes:expect:5.10
-
cpe:2.3:a:don_libes:expect:5.11
-
cpe:2.3:a:don_libes:expect:5.12
-
cpe:2.3:a:don_libes:expect:5.13
-
cpe:2.3:a:don_libes:expect:5.14
-
cpe:2.3:a:don_libes:expect:5.15
-
cpe:2.3:a:don_libes:expect:5.16
-
cpe:2.3:a:don_libes:expect:5.17
-
cpe:2.3:a:don_libes:expect:5.18
-
cpe:2.3:a:don_libes:expect:5.19
-
cpe:2.3:a:don_libes:expect:5.2
-
cpe:2.3:a:don_libes:expect:5.20
-
cpe:2.3:a:don_libes:expect:5.21
-
cpe:2.3:a:don_libes:expect:5.22
-
cpe:2.3:a:don_libes:expect:5.23
-
cpe:2.3:a:don_libes:expect:5.24
-
cpe:2.3:a:don_libes:expect:5.25
-
cpe:2.3:a:don_libes:expect:5.26
-
cpe:2.3:a:don_libes:expect:5.27
-
cpe:2.3:a:don_libes:expect:5.28
-
cpe:2.3:a:don_libes:expect:5.29
-
cpe:2.3:a:don_libes:expect:5.3
-
cpe:2.3:a:don_libes:expect:5.30
-
cpe:2.3:a:don_libes:expect:5.31
-
cpe:2.3:a:don_libes:expect:5.4
-
cpe:2.3:a:don_libes:expect:5.5
-
cpe:2.3:a:don_libes:expect:5.6
-
cpe:2.3:a:don_libes:expect:5.7
-
cpe:2.3:a:don_libes:expect:5.8
-
cpe:2.3:a:don_libes:expect:5.9
-
cpe:2.3:o:conectiva:linux:6.0
-
cpe:2.3:o:conectiva:linux:7.0
-
cpe:2.3:o:redhat:linux:7.0