CVE-2000-0703
suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.07% probability · 63th percentile
- CISA KEV
- Not listed
- Affected
- larry wall/perl
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0022.htmlExploit, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0086.html
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0113.html
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0153.html
- http://www.calderasystems.com/support/security/advisories/CSSA-2000-026.0.txtPatch, Vendor Advisory
- http://www.novell.com/linux/security/advisories/suse_security_announce_59.html
- http://www.redhat.com/support/errata/RHSA-2000-048.html
- http://www.securityfocus.com/bid/1547Exploit, Patch, Vendor Advisory
- http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000017.html
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0022.htmlExploit, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0086.html
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0113.html
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0153.html
- http://www.calderasystems.com/support/security/advisories/CSSA-2000-026.0.txtPatch, Vendor Advisory
- http://www.novell.com/linux/security/advisories/suse_security_announce_59.html
- http://www.redhat.com/support/errata/RHSA-2000-048.html
- http://www.securityfocus.com/bid/1547Exploit, Patch, Vendor Advisory
- http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000017.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.