CVE-2000-0693
pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate "cp" program.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.02%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate "cp" program.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.02% probability · 61th percentile
- CISA KEV
- Not listed
- Affected
- tech-source/raptor gfx pgx32
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.htmlExploit, Vendor Advisory
- http://www.osvdb.org/1501
- http://www.securityfocus.com/bid/1563Exploit, Patch, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.htmlExploit, Vendor Advisory
- http://www.osvdb.org/1501
- http://www.securityfocus.com/bid/1563Exploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.