A100900-1Vendor advisory
http://www.atstake.com/research/advisories/2000/a100900-1.txt CVE-2000-1074
Netscape iCal 2.1 Patch2 - iPlanet iCal 'csstart' Local Privilege Escalation
Record summary
CVE-2000-1074 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNetscape iCal 2.1 Patch2 - iPlanet iCal 'csstart' Local Privilege EscalationExploitDB exploitby @stakeNot analyzed1 file
References
57209vdb entry
http://www.osvdb.org/7209 1769vdb entry
http://www.securityfocus.com/bid/1769 ical-csstart-gain-access(5757)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5757 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-1074