Vulnerabilities
Vulnerable Software
Don Libes:  >> Expect  Security Vulnerabilities
expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.
CVSS Score
7.2
EPSS Score
0.001
Published
2001-07-19
mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.
CVSS Score
7.5
EPSS Score
0.007
Published
2001-04-11


Contact Us

Shodan ® - All rights reserved