CVE-2001-1145
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to…
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories.
- CVSS 2.0
- 6.2 MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 0.30% probability · 22th percentile
- CISA KEV
- Not listed
- Affected
- freebsd/freebsd · netbsd/netbsd · openbsd/openbsd
- Source
- cve@mitre.org
References
- ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:40.fts.v1.1.asc
- http://archives.neohapsis.com/archives/netbsd/2001-q3/0204.htmlPatch, Vendor Advisory
- http://www.iss.net/security_center/static/8715.php
- http://www.openbsd.org/errata28.htmlPatch
- http://www.osvdb.org/5466
- http://www.securityfocus.com/bid/3205
- ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:40.fts.v1.1.asc
- http://archives.neohapsis.com/archives/netbsd/2001-q3/0204.htmlPatch, Vendor Advisory
- http://www.iss.net/security_center/static/8715.php
- http://www.openbsd.org/errata28.htmlPatch
- http://www.osvdb.org/5466
- http://www.securityfocus.com/bid/3205
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.