Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2001-1374
Disclosure Date: July 19, 2001 (last updated February 22, 2025)
expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.
0
Attacker Value
Unknown
CVE-2001-1467
Disclosure Date: April 11, 2001 (last updated February 22, 2025)
mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.
0